Publication date: August 26, 2026
Authors: attorney-at-law (radca prawny) K. Jakub Gładkowski (corporate practice, court and regulatory representation), attorney-at-law (radca prawny) Małgorzata Kiełtyka (M&A, high-technology and highly regulated sectors) – KG Legal Kiełtyka Gładkowski Spółka Partnerska Kancelaria Radców Prawnych; iSTART1 programme.
This material is of a popular-science and informational nature. It does not constitute legal advice or a binding opinion. Before citing any specific provision, the current consolidated version in EUR-Lex and the current entry in the Polish Journal of Laws (Dziennik Ustaw) should be verified in each case.

The Russo-Ukrainian conflict has become a lens in which the future of dual-use unmanned technology is brought into focus – and, at the same time, a barometer of the direction its regulation will take. Within two to three years, technological progress has occurred which, in peacetime conditions, would have taken decades. This article combines two perspectives: a technological taxonomy of drone warfare and a map of the legal environment of the European Union and Poland, encompassing nine mutually interpenetrating regulatory pillars – from product certification and airspace management, through artificial intelligence, export control, defence financing, satellite communications, cybersecurity and personal data protection, to international law and the national regime.
The thesis to be verified is that the legal regime of the UAV sector is structurally dual-track: on the civil track, law operates as a consequence of need and as a risk-dampening factor, whereas on the defence track it operates as a driver of development. The mechanism separating the two tracks is the military exclusion in Article 2(3) of the Artificial Intelligence Act and the analogous defence exclusions in successive instruments, while the line of dispute is the increasingly blurred dual-use boundary. We analyse seven concrete points of friction between the tracks and formulate a practical qualification map and a 2026–2028 compliance calendar for manufacturers, operators and investors in this sector.
Keywords: unmanned aircraft, dual use, Artificial Intelligence Act, high-risk systems, autonomous weapon systems, export control, U-space, NIS2, CER, personal data protection, European Drone Defence Initiative.
The impulse to look at the drone problem not merely as a tactical phenomenon but as a growing strategic threat to Europe comes from reports circulating in the analytical and milblogger space – based on statements of Ukrainian military intelligence (HUR) – that Russia is already producing more jet-powered variants of the Geran-4 and Geran-5 than piston-engined Geran-2s, with figures in the order of approximately 3,000 jet platforms per month against approximately 2,800 piston variants. Assessments of this kind, even if they call for source-related caution, are of significant analytical importance: they show that the scale of Russian production of unmanned means of aerial attack may exceed the framework of a war of attrition against Ukraine and may be perceived as a capability able to support a broader campaign of pressure or threat directed at European states. In this sense, the drone problem is no longer an exclusively military issue, but also a stimulus for a fresh reading of the legal environment of unmanned technologies in Europe – from aviation law, through export control and AI, to cybersecurity, the protection of critical infrastructure and state security.[1]
On the night of 9/10 September 2025, a dozen or so unmanned aircraft flew into Polish airspace; some of them were shot down by NATO aircraft. This was not an isolated incident – the Romanian government had reported violations as early as January 2025, and in August of the same year a Russian Geran-2-type platform came down near Osiny in eastern Poland. The September event, however, carried a different weight: it triggered consultations under Article 4 of the Washington Treaty, led to the launch of NATO’s operation _Eastern Sentry_, and, in the EU dimension, to the announcement of a “drone wall”, subsequently transformed into the European Drone Defence Initiative (EDDI) and Eastern Flank Watch.
The current phase of the Russo-Ukrainian conflict makes it plain that both sides are developing unmanned technologies according to different operational logics and economics of use. The Russian side has to a greater extent expanded the segment of drones performing a function complementary to classic means of aerial attack: decoys, platforms imitating the actual strike assets, and cheap carriers used to saturate air defence and force the expenditure of effectors on the Ukrainian side. The Ukrainian side, conversely, is developing more broadly the segment of long-range drones with a real strike function, whose principal purpose is to strike rear-area infrastructure, including refineries, logistics and other objects of high operational value. This difference matters not only militarily but also in legal-regulatory terms, because it translates into different risk profiles as regards the qualification of dual-use technology, liability for the use of means of aerial attack, the protection of critical infrastructure, and the economics of air defence. In practice, the Russian model relies to a considerable degree on forcing a costly defensive reaction on the adversary’s side, whereas the Ukrainian model aims at the asymmetric striking of rear-area targets using relatively cheap platforms, which further deepens the problem of cost disproportionality between a cheap drone and an expensive defensive effector, such as the missiles of the S-300, S-400, Tor or Pantsir systems. In this sense, the conflict is a lens not only of the development of technology, but also of the transformation of the regulatory logic itself: law must now contend not with a single device, but with entire models of the operational use of unmanned technologies.[2]
For the lawyer, however, something else is most important. The facts give rise to questions about an asymmetry which is the crux of the entire regulatory problem: against platforms with a unit cost counted in thousands of dollars, systems were used whose single effector should cost hundreds of thousands. This cost asymmetry is not merely a budgetary problem. It forces the burden of defence to be shifted onto solutions that are cheap, mass-produced and increasingly autonomous – and therefore precisely onto that class of technology which European Union law regulates most cautiously on the civil side and almost not at all on the military side.
The new regulatory architecture of drone security: from EU strategy to the obligations of critical infrastructure operators and AI systems
Over the following months, the legislative tempo concerning unmanned systems accelerated in a manner unprecedented for this sector. The existing drone regulations had concentrated primarily on aviation safety, the rules for conducting operations, and technical requirements for operators and manufacturers. In 2026, however, a significant shift of regulatory emphasis took place: the drone began to be treated not only as an aviation device, but also as a potential tool of threat to critical infrastructure and as a system that may be subject to the requirements of artificial intelligence regulation.
The first element of this new architecture was the Action Plan on Drone and Counter Drone Security (COM(2026) 81 final) presented by the European Commission on 11 February 2026.[3] This document does not constitute a legally binding act within the meaning of Article 288 of the Treaty on the Functioning of the European Union,[4] but has the character of a European Commission communication – a political and programmatic instrument belonging to the category of so-called soft law. It does not establish direct obligations for Member States, undertakings or critical infrastructure operators, but it sets the direction of the European Union’s future legislative and organisational actions.
The significance of this document lies above all in a change in the way threats connected with unmanned aircraft are perceived. The Commission indicated that the rapid development of drone technologies, their commercial availability and the possibility of their use by entities conducting hostile activities make it necessary to build a European security system encompassing both protection against unauthorised drone operations (counter-drone) and the strengthening of the resilience of Member States’ infrastructure.
The Action Plan provides for the development of Member States’ capabilities in detecting, identifying and neutralising threats caused by drones, better information exchange between security authorities, and the development of counter-drone technologies. Particular importance was attached to the protection of critical infrastructure, military facilities, the external borders of the European Union, and places particularly exposed to the unlawful use of drones.
The European Commission’s Action Plan should accordingly be treated as the first level of the new regulation – the strategic level. It does not yet impose specific legal obligations, but it creates the political justification for subsequent legislative changes at national and EU level.
The second level was the intervention of the Polish legislator. The Act of 29 May 2026 amending the Act on Crisis Management and certain other acts introduced solutions enabling the use of jamming devices in the protection of critical infrastructure.[5]
This amendment[6] is of particular importance because, for the first time in the Polish legal system, an express basis was created for the application of measures interfering with the communications or control of unmanned aircraft by entities connected with the protection of critical infrastructure. It must, however, be precisely noted that the legislator did not grant critical infrastructure operators an independent right to use jamming devices.[7] The legal construction was shaped at two levels.
First, Article 16c,[8] added to the Act on Crisis Management, grants the critical infrastructure operator the competence to take a decision on the admissibility of the use of specified devices.
That provision reads:
“In order to ensure the protection of critical infrastructure, the critical infrastructure operator (…) may take a decision on the admissibility of the use of the devices referred to in paragraph 1, for the time necessary for the performance of activities by security staff of specialist armed security formations (…)”.
Second, the technical scope of those measures follows from the provisions of the Aviation Law, in particular Article 156ze(1), which sets out the possibility of using devices serving to counter unmanned aircraft.
Under that provision, such devices may be used for the purpose of:
“interfering with or taking over control of an unmanned aircraft, interfering with the flight control signal or the navigation signal enabling the flight of that aircraft”.[9]
In practice, this means that the critical infrastructure operator has obtained a new power of a decision-making character, whereas the physical use of the devices remains tied to the activities of the staff of specialist armed security formations (SUFO). This solution is a compromise between the need for effective protection of strategic facilities and the necessity of limiting the risk of uncontrolled use of devices capable of interfering with communications or navigation systems.
The explanatory memorandum to the bill[10] stated that the purpose of the regulation is to increase the resilience of critical infrastructure and to provide operators with tools corresponding to contemporary threats, in particular threats making use of unmanned systems.
The third level of regulation was the modification of the timetable for the application of the provisions of the EU Artificial Intelligence Act.
On 29 June 2026, the Council of the European Union approved an amendment to Regulation (EU) 2024/1689 of the European Parliament and of the Council laying down harmonised rules on artificial intelligence (the AI Act).[11] This amendment did not change the AI Act’s basic risk-based regulatory model, but postponed the dates on which part of the obligations concerning high-risk systems begin to apply.
The most significant change was the extension of the preparatory period for providers of high-risk AI systems. The regulation was intended to enable undertakings, supervisory authorities and standardisation institutions to prepare the appropriate technical and organisational mechanisms, including conformity standards, risk assessment procedures and quality management systems.
This change is also relevant for the drone sector. Contemporary unmanned systems increasingly use artificial intelligence algorithms for autonomous navigation, object identification, image analysis or operational decision-making. In consequence, particular applications of drones may simultaneously be subject to aviation law regulations, provisions concerning the security of critical infrastructure, and the requirements of the AI Act.
By way of example, Article 113 of Regulation (EU) 2024/1689, which sets out the timetable for the application of the AI Act’s provisions, was amended as regards the dates of applicability of the rules concerning high-risk systems, postponing the full application of part of the obligations to later dates.[12]
As a result, in 2026 a multi-level regulatory architecture concerning a single device came into being. At European Union level, the European Commission set the strategic direction of the development of drone security policy through the non-binding Action Plan. At national level, Poland created a mechanism for the protection of critical infrastructure enabling the use of counter-drone measures. At the technological level, the AI Act laid down the principles of the responsible use of artificial intelligence systems employed in autonomous devices.
Three different regimes. Three different regulatory logics. And all of them concern the same device.

The history of military technology knows few moments in which the development curve breaks as abruptly as in Ukraine after 2022. Commentators[13] estimate that the technological leap[14] in the field of unmanned aircraft accomplished during two to three years of war would, in the absence of an arms race, have taken 20–30 years.[15] As to the period, it must be assessed that the thesis itself is fundamentally true, but the formulation “20–30 years” is not a scientific claim easily attributable to a single source. It is rather a metaphor used by military analysts, representatives of the defence industry and commentators, who describe a step-change acceleration of the innovation cycle under the influence of the war. In the space of only two to three years, drones travelled the road from specialised reconnaissance tools to mass-deployed combat systems, encompassing cheap single-use platforms, unmanned swarms, systems resistant to electronic jamming, and solutions using artificial intelligence. In the view of many military analysts, this conflict has shortened the development cycles of unmanned technologies in a way that, in peacetime conditions, would correspond to a multi-year or even multi-decade process of evolution.[16]
This paradox of acceleration has its source not in success but in failure.[17] The original plan of a lightning resolution – seizing the capital within a week and taking control of the south of the country – collapsed already in the cyber phase, when the operation intended to paralyse the digital administration, banking and state budget did not translate into the country’s military collapse. The result was a positional stalemate in the east – trench warfare reminiscent of the fronts of a hundred years ago.
And it was precisely this stalemate, not manoeuvre, that became the incubator of innovation. Tactical pressure in an environment in which neither side can gain a conventional advantage forced a cascade of technological solutions: from commercial observation drones, through mass-scale FPV drones, to satellite-controlled long-range platforms with elements of autonomy.
It is worth emphasising that this mechanism was to a considerable extent civilian in its genesis. The drone revolution did not come out of the laboratories of the great arms concerns, but out of the model-making market, out of commercial consumer electronics and out of open-source software. A manufacturer which in 2021 was selling a platform for power-line inspection was in 2023 delivering the same design with a different payload configuration. The law, which for two decades had been building separate regimes for civil aviation and for armaments, found itself confronted with a product that crosses that boundary without any design modification.
For a lawyer serving entities in the high-technology sector, the paradox of acceleration has a practical dimension. It gives rise to the question that is the axis of this text: does law in this area merely react to a technology which the conflict has outpaced, or has it itself become an instrument of acceleration – and perhaps, in some segments, an instrument of its extinguishment.
The answer, which we substantiate in the remainder of this text, is: law performs three different roles simultaneously in this sector, and which of them is activated is decided not by the technology but by the qualification of the purpose of use. And that qualification is, in the case of dual-use products, inherently unstable.
The structure of the argument is as follows. Part 2 presents the technological taxonomy of drone warfare – without it, legal analysis operates in a vacuum, because each of the regulatory regimes attaches legal consequences to specific technical features (mass, range, presence of sensors, degree of autonomy, type of link). Part 3 maps the legal environment of the European Union and Poland, divided into nine pillars.

Part 4 analyses seven points of friction at which these pillars collide with one another – it is there that the undertaking’s real legal risk is concentrated. Part 5 formulates the thesis of the dual-track nature of the regime. Part 6 translates the analysis into transactional and compliance practice, together with a compliance calendar up to 2028.
The point of departure for any legal analysis must be the differentiation of categories. It is a fundamental error – also in the regulatory debate – to treat the “drone” as a single class of devices. A more apt analogy here is to optics and photography: there is no single universal lens for every photograph, because each type of shot – macro, portrait, telephoto, wide-angle landscape – requires a different optical construction, a different focal length and a different compromise between reach and field of view. It is exactly the same with drones and counter-drone systems: there is no single “anti-drone system”; there are systems countering specific categories of platforms, matched to their signature, range and mode of communication. This differentiation is not merely descriptive but legal in character – it determines product qualification, the export regime and the scope of compliance obligations.
This differentiation has directly normative consequences. At the level of product qualification, the mass, construction and intended purpose of the platform determine its place in the EU UAV regime, in particular in Delegated Regulation (EU) 2019/945 and Implementing Regulation (EU) 2019/947, which treat product classes and the “open”, “specific” and “certified” categories of operations differently; in practice this means that the same aircraft may, as a product, remain in lawful civil circulation while at the same time, with a different mode of use or retrofitting, pass into the area of heightened regulatory risk. At the level of the export regime, the identical differentiation decides whether a component, software, sensor, communications module or navigation system falls within the scope of Regulation (EU) 2021/821 as a dual-use product, which may trigger an authorisation requirement, an end-user assessment and a proliferation risk analysis. At the level of compliance obligations, in turn, what matters are not only the physical features of the drone but also its data and autonomy functions: the presence of cameras, sensors or AI modules may in parallel trigger the requirements of the GDPR, cybersecurity, information security and – outside the scope of the military exclusion – the obligations arising from the AI Act. As a result, in the UAV sector it is not enough to ask “what is the product”; the key question becomes in what chain of use, circulation and liability the product operates.
The importance of this differentiation lies in the fact that, in the UAV sector, technical categories translate into different normative consequences in several overlapping legal regimes at once. First, at the level of product and operational qualification, features such as take-off mass, communications architecture, scope of autonomy or type of payload affect the classification of the platform in the light of Delegated Regulation (EU) 2019/945 and Implementing Regulation (EU) 2019/947, and thus the admissibility of its placing on the market and the mode of its lawful operation. Second, at the level of export control, the same features may determine whether specific components, sensors, navigation modules, software or technical documentation are covered by the regime of Regulation (EU) 2021/821, which triggers licensing obligations, end-user assessment and proliferation risk assessment. Third, at the level of functional compliance, what matters is no longer only the material features of the platform itself, but also its data-processing, observation and decision-support functions: the use of optical sensors, thermal-imaging sensors, remote identification systems or image-analysis algorithms may in parallel trigger requirements arising from the GDPR, cybersecurity regulation and – outside the scope of the military exclusion – the obligations laid down in the AI Act. In this sense, the legal qualification of a drone is not a one-off act but a multi-layered process, dependent on construction, function, context of use and the architecture of circulation.[18]
A separate phenomenon, irreducible to any of the above categories, is the drone swarm. Whereas the existing taxonomy ordered drones according to the features of a single platform – mass, range, mode of communication, degree of autonomy – the swarm is an emergent phenomenon at the level of many platforms operating as one system. Three elements are key here: iteration and coordination between units (drones exchange data on position, target and status in real time, often via a mesh network, with no single point of failure), distributed processing of sensor data (imagery and telemetry from many platforms are aggregated and classified jointly, which increases target-detection effectiveness beyond the sum of individual sensors), and collective control by a single operator or a supervisory algorithm which allocates tasks among the units of the swarm. Ukrainian deployments of this technology – including autonomous swarming systems used since 2025 for mine-laying and target engagement, and large-scale operations combining several dozen to several hundred platforms in a single strike – show that the swarm is no longer an experiment but an operational reality. This has serious legal consequences which remain unresolved to date: whether the swarm should be qualified as a single system subject to a single conformity assessment or as a collection of separate products; who bears responsibility for a decision taken at swarm level when no single platform takes it independently; and how the data protection and radio spectrum management regime is to treat a network whose nodes come into being and disappear in flight.[19]
This differentiation is not merely terminological or descriptive in character, but produces direct legal effects. The individual technical properties of an unmanned aircraft constitute the triggering conditions for different regulatory regimes of European Union law and national law. In practice, this means that a change in one technical parameter of a drone may lead to a fundamentally different legal qualification of the same device.
The first such parameter is the Maximum Take-Off Mass (MTOM). Commission Delegated Regulation (EU) 2019/945 establishes classes of unmanned aircraft systems (C0–C6), whose assignment takes place, among other things, with regard to technical parameters, in particular mass, speed and system equipment. This classification is not purely technical in character – it determines the possibility of conducting operations in the appropriate subcategories of the “open” category provided for in Commission Implementing Regulation (EU) 2019/947 and affects the manufacturer’s obligations connected with conformity assessment and product class marking.[20]
The significance of mass is also revealed at the level of the operator’s obligations. Under Article 14 of Implementing Regulation (EU) 2019/947, the operator of an unmanned aircraft system is subject to a registration obligation, inter alia, where it operates an aircraft with a maximum take-off mass of at least 250 g or – regardless of mass – an aircraft equipped with a sensor capable of capturing personal data, unless the device meets the conditions provided for toys within the meaning of Directive 2009/48/EC. The 250 g mass thus constitutes one of the fundamental legal thresholds in the European drone regulatory system.[21]
The second parameter of fundamental importance is the drone’s equipment with sensors enabling the capture of personal data, above all optical cameras, thermal-imaging cameras, LiDAR scanners or other devices allowing the identification of natural persons. In such a case, the General Data Protection Regulation (GDPR) applies. Data recorded by a drone may constitute personal data within the meaning of Article 4(1) GDPR, which entails the necessity of ensuring a legal basis for processing in accordance with Article 6 GDPR, complying with the principles set out in Article 5 GDPR and – in the case of operations creating a high risk to the rights and freedoms of natural persons – carrying out a data protection impact assessment in accordance with Article 35 GDPR. These obligations arise regardless of the mass of the aircraft, and therefore also in relation to the smallest drones weighing under 250 g, if they are equipped with devices enabling the capture of personal data.[22]
This approach is confirmed in the case law of the Court of Justice of the European Union. In its judgment of 11 December 2014 in Case C-212/13, Ryneš, the Court held that the recording of images enabling the identification of natural persons constitutes the processing of personal data, even if it takes place with the use of devices monitoring the surroundings of private property. Although the case concerned video surveillance, the conclusions flowing from that judgment apply mutatis mutandis also to unmanned systems equipped with cameras or other observation sensors.[23]
A further feature determining the legal regime is the character of the equipment and payload. Regulation (EU) 2021/821 of the European Parliament and of the Council establishes the Union’s system for the control of exports of dual-use items. The qualification of a drone or its components for the list of dual-use items is decided not only by flight parameters but also by the technical capabilities of the device, such as range, autonomy, navigation systems, observation equipment, high-resolution cameras, data transmission systems or specialised sensors. In consequence, two seemingly similar drones may be subject to entirely different export obligations solely on account of differences in their equipment or technical capabilities.[24]
Even more complex is the legal qualification of systems using artificial intelligence. The degree of flight autonomy alone does not automatically determine the applicability of the AI Act. It must first be established whether the given solution constitutes an “AI system” within the meaning of Article 3 of Regulation (EU) 2024/1689. Only at the next stage is it necessary to assess whether the system belongs to the high-risk category in accordance with Article 6 of that regulation and Annexes I and III. This means that two drones with identical flight parameters may be subject to different regulatory obligations solely on account of differences in the software responsible for autonomous navigation, object identification, image analysis or operational decision-making.[25]
In consequence, the legal qualification of an unmanned aircraft does not follow from a single technical feature, but from the configuration of its constructional, functional and operational properties. The same drone may simultaneously be subject to aviation law regulations, personal data protection provisions, the dual-use item control regime, provisions concerning the protection of critical infrastructure and – in specific cases – Regulation (EU) 2024/1689 (the AI Act). This signifies a transition from the classic model of sectoral regulation to a model of functional regulation, in which different branches of law simultaneously apply to the same device, protecting different legal goods: aviation safety, privacy, state security, control of trade in technologies and the safety of artificial intelligence systems.
The lowest tier consists of commercial multirotor drones (the Chinese DJI Mavic,[26] Ukrainian equivalents of the Zoom class). Their role is to provide situational awareness – the category that decides the success of every assault and every defence. A contemporary soldier with an overhead picture operates in an entirely different reality from one who scans the field with his eyes.
In the Ukrainian trade and military-technology discourse,[27] the designation ZOOM refers to a specific reconnaissance platform developed by the Ukrainian company Frontline / Frontline Robotics, presented as an alternative to the Chinese DJI Mavic drones. It is a light multirotor observation drone intended for reconnaissance tasks, fire correction and building situational awareness at the tactical level, and therefore for the same operational niche which for a long time was dominantly occupied at the front by Mavic platforms. In this sense, the “Ukrainian equivalent of the Mavic of the ZOOM class” should be understood not as a formal technical category but as the proper name of a domestic platform positioned in the segment of light reconnaissance drones with a substitutive function vis-à-vis DJI. The available sources[28] also indicate that ZOOM forms part of a broader Ukrainian trend of building domestic Mavic analogues in order to reduce dependence on foreign civilian commercial systems.
Importantly, despite rapid development these platforms have not disappeared – on both sides of the front, civilian Mavics are still used, whose sole task is to “hang in the air and watch”. This is an observation of primary legal importance: the most numerous category of platforms used in the conflict consists of mass-produced consumer products, placed on the market under the civil regime, with CE marking, in classes C0–C2. The same unit which yesterday was subject to Implementing Regulation (EU) 2019/947 as an operation in the open category is today carrying out a reconnaissance task outside any EU regime.
The DJI Mavic constitutes a model example of the detachment of the product from the purpose of use. As a commercial product, it was designed and placed on the market for the needs of the civil market: photography, inspection, surveying, recreation and light professional applications. In that order, its legal status is determined by the classic instruments of EU aviation law and product law – in particular the requirements of CE marking, the product classes under Delegated Regulation (EU) 2019/945, the operating rules under Implementing Regulation (EU) 2019/947, the operator’s obligations, remote identification, geographical zones, registration and – depending on the sensor configuration – data protection requirements. However, the moment that same unit is used on contested territory to build situational awareness, correct fire or conduct military reconnaissance, the logic for which the EU civil aviation regime was built ceases to operate. The product itself as a thing does not change, but its operational function changes, and with it the normative order changes: from the area of product safety and lawful civil operation we pass into the area of military operations, military logistics, the law of armed conflict, export control and state security. It is precisely for this reason that, in the UAV sector, the legal nature of a platform is increasingly determined not by its construction but by the chain of use into which it is incorporated.
A good counterpoint to this transformation is the example of the Ukrainian Mavic equivalents, such as the ZOOM developed by the above-mentioned Frontline Robotics. Where the manufacturer communicates[29] that a given complex has been entered in the NATO Codification System (NCS) and has received a NATO Stock Number (NSN), this means not so much the obtaining of civil certification as the product’s entry into the common language of NATO defence logistics: the item is unambiguously identified, classified and prepared to function within the system of supply, storage and military interoperability. The NSN is therefore a catalogue-logistics designation, not a mark of quality or an authorisation for marketing in the sense of consumer law or civil aviation law. The juxtaposition of the Mavic with a platform codified in the NATO system well illustrates the institutional shift: the first product begins its life in the regime of civil commercialisation, while the second is from the outset positioned as an element of the defence architecture and the military supply chain. This difference does not consist solely in technology, but in normative embedding – that is, in whether the product is designed for the civil market or for the order of military logistics and allied interoperability.[30]
The current combat standard in the front-line zone is the FPV (first person view) drone – single-use platforms controlled from a first-person perspective through goggles. This is not, however, a weapon of the individual soldier: the operation of a single drone requires a team of 3–4 persons (pilot, relay operator, sapper, frequently a navigator). The FPV is a squad weapon, like a mortar or a heavy machine gun. One team is able to carry out 25–30 sorties a day, consuming a corresponding number of single-use platforms.[31]
The scale of this revolution has above all an economic and institutional dimension. It is no accident that industry analyses describe FPV as the “$1,000 revolution”: the essence of the breakthrough lies not solely in the platform itself, but in the relationship between the low unit cost of the means of attack and the high cost of countering it, as well as in the possibility of rapidly scaling production on the basis of a dispersed component market, a simple assembly architecture and short iteration cycles. In this sense, FPV is not merely a new category of drone but a new model of the economics of war – a model in which a relatively cheap, partly standardised and rapidly modifiable platform can generate tactical and operational effects disproportionate to its price. That is precisely why the weight of the analysis shifts from the question of the individual product to the question of the production ecosystem, the capacity for its continuous reproduction, and the institutional conditions that enable the transition from field improvisation to mass production.[32]
In the case of Ukraine, this capacity is no longer solely the effect of spontaneous industrial mobilisation, but results from the construction of an organised, state-supported defence tech ecosystem, centred on the Brave1 platform.[33] Brave1 was launched on 26 April 2023 as a governmental defence tech cluster, co-created by the Ministry of Digital Transformation of Ukraine, the Ministry of Defence, the General Staff of the Armed Forces of Ukraine, the National Security and Defence Council and the Ministry of Strategic Industries,[34] with the implementation layer carried out by the Innovation Development Fund. From a legal perspective, this is not a classic commercial-law company nor a single procurement procedure, but rather a public coordination platform combining grant, testing, matchmaking and acceleration functions. Officially, Brave1 describes its role as supporting the development of defence technologies through organisational, informational and financial support for projects, and the platform’s successive initiatives – including grant programmes, a defence innovation marketplace and projects carried out with international partners – show that it operates as an intermediate layer between the technological idea, the prototype, military testing, IP protection and further implementation into procurement or operational use. It is therefore an institutional mechanism for mobilising defence innovation, not a separate, homogeneous statutory regime.
The significance of Brave1 for the FPV market lies in the fact that this platform aggregates dispersed manufacturers and lowers the threshold of entry into the defence sector, shortening the road from design to implementation. Analytical sources indicate that around 1,500 defence tech companies and start-ups are gathered around Brave1, with some more recent analyses speaking of an even greater number of entities functioning within this ecosystem.[35] From the point of view of this report, however, more important than the number itself is that Brave1 produces an architecture of scale: new entities can enter the sector via a grant, testing, validation, contact with the military user, intellectual property protection and entry into the procurement circuit, without having to pass immediately through the classic, heavy model of the armaments industry. It is precisely this institutional model that explains why Ukraine was able to move from the early phase of improvisation and purchases from the commercial market to a phase in which drone production began to be treated as a mass state capability.[36]
The volumes of this production are unprecedented. Industry analyses and statements by representatives of the Ukrainian authorities cite figures of the order of about 800 thousand drones in 2023, about 2 million in 2024, production capacities reaching 4 million annually, and subsequently procurement plans covering about 4.5 million FPV drones in 2025. In parallel, declared targets for 2026 have also appeared in public circulation, according to which Ukraine would aim for a level of 7 million drones annually, presented as a volume many times exceeding American production. Even if the individual figures must be treated with caution and a distinction must be drawn between actual production, production capacity, procurement plan and political-industrial target, the direction itself is unambiguous: Ukraine has transformed drones – especially FPV – from an auxiliary technology into an industrial strategic resource, whose development depends no longer solely on the technical capability of an individual manufacturer, but on state-supported organisational, grant, testing and procurement infrastructure. In this sense, Brave1 operates as a multiplier of production sovereignty: it not only supports a specific project, but builds the conditions in which the entire sector can reproduce itself, scale and become independent of imports of ready-made platforms.[37]
In the legal and economic layer, it is particularly significant that Brave1 is not limited to the distribution of public funds from the Ukrainian budget. Over time, this platform has also been opened to international grants, partnerships with Western states and institutions, and channels of cooperation with the NATO procurement and interoperability environment. This means that the Ukrainian FPV market is today developing at the intersection of national law, mechanisms of public support for innovation, defence cooperation with foreign partners, and the wartime logic of rapid testing and deployment. From this perspective, the success of Ukrainian unmanned production should not be described solely as an industrial success, but also as a success in the design of institutional instruments which have made it possible to combine thousands of smaller entities into one functional ecosystem capable of delivering effects at the scale of millions of units annually.
The mass character of FPV production and the dispersal of suppliers in Ukraine are not solely a spontaneous effect of wartime mobilisation, but the result of the institutional ordering of the defence tech ecosystem. The importance of Brave1 lies precisely in the fact that this platform does not replace the individual manufacturer or the classic armaments industry, but creates an organisational framework within which hundreds – and, according to the available sources, around one and a half thousand – entities can function as elements of a single innovation-production system. From a legal and economic perspective, Brave1 is therefore not merely a sectoral cluster, but an instrument of the state ordering of defence innovation: it shortens the road from idea to test, from test to grant, from grant to implementation, and in the longer perspective – to an order or operational use. This architecture can be described most cleanly at three levels: institutional, project and operational.
1. The institutional level
At the institutional level, Brave1 functions as a governmental initiative / defence tech cluster of Ukraine, launched on 26 April 2023 and co-created by the key state organs responsible for security, defence and technology policy, in particular the Ministry of Digital Transformation of Ukraine, the Ministry of Defence, the General Staff of the Armed Forces of Ukraine, the National Security and Defence Council and the Ministry of Strategic Industries. The official description further indicates that the initiative is implemented by the Innovation Development Fund, which allows Brave1 to be treated as an instrument embedded at the interface of public administration, the security sector and state innovation policy. It does not follow from the publicly available materials that Brave1 is a self-standing entity established by a single separate statute or a single specific normative act; it is more accurate to conceive of it as a state coordination platform whose status results from the combination of the competences of public institutions and the implementation mechanisms of the innovation development fund. It is precisely this institutional embedding that explains why Brave1 was able to become a focal point for a broad ecosystem of drone manufacturers, including FPV platforms, instead of remaining merely a grant programme or a sectoral initiative of limited reach.
2. The project level
At the project level, the Brave1 cluster has been linked with the European Union-financed undertaking EU4UA Defence Tech, functioning publicly under the title “Strengthening the Innovation Capacities of the Ukrainian Defence Technological Industrial Base”. It follows from the available sources that this is not a self-standing act of secondary Union law of the kind of a regulation or directive, but an implementation and grant project, officially announced by the Delegation of the European Union to Ukraine within the EEAS structure, financed by the European Union and implemented by BRDO in cooperation with Brave1. In this architecture, Brave1 plays the role of the Ukrainian cluster and access point to the defence tech ecosystem, while the project layer gives this ecosystem an additional dimension of internationalisation, grant support and linkage with the policy of strengthening the Ukrainian defence technological and industrial base. The formal specification of this layer does not, however, take place through a single “founding act” of statutory or Union rank, but through a set of project and operational documents: the EEAS institutional communication, the BRDO project description and the regulations of the grant programme.
Particularly significant from the point of view of a legal report is that the project layer finds its concrete expression in the draft grant agreement concluded between the Innovation Development Fund and the beneficiary being the developer of a specific technology.[38] This means that entry into the Brave1 / EU4UA Defence Tech system does not lead directly to a relationship with a Union institution in the typical model of a European Commission grant, but to a contractual relationship governed by Ukrainian law with a public entity on the Ukrainian side. From this perspective, the project level of Brave1 should be understood as a space in which the dispersed sector of manufacturers – including creators of FPV technology – is drawn into a structured model of public support, but at the price of entering a specific contractual regime. Of particular importance here are the clauses concerning ownership and intellectual property rights: the draft grant agreement provides that ownership rights and rights to IP created with the use of grant funds as a rule remain with the developer, which at first sight may suggest a model friendly to commercialisation and to the retention of private control over the result of the project. At the same time, however, the same draft agreement grants the fund a broad, free-of-charge entitlement to use – at its own discretion – all documents and information obtained in the course of the granting of the grant, insofar as such use remains consistent with existing IP rights. This construction therefore does not lead to a simple takeover of IP by the state, but creates a hybrid model of control in which formal ownership remains with the developer, while the fund secures for itself a strong position of access and use in relation to the documentation and information connected with the project. In legal practice, this means that the key question is no longer only who owns the result, but also how broadly the scope of “documents and information” will be interpreted, what technical material is transferred to the fund, and where the boundary runs between the authorised use of documentation and indirect interference with the developer’s economic exclusivity (in accordance with Article 5(1) and (2) of the grant form: “Ownership rights and property rights to intellectual property created as a result of the use of Grant funds belong to the Developer, unless otherwise specified by the Developer.”; ”The Developer grants the Fund the right to use, free of charge and at its own discretion, all documents and information obtained in the process of providing the Grant, if such use complies with existing intellectual property rights”) (see footnote 38).
This tension is further reinforced by the clause on governing law and disputes, according to which the agreement is to be interpreted under the law of Ukraine, and any disputes are to be resolved first by way of negotiations and then in accordance with the procedure provided for by Ukrainian law and/or before a court. In the functional sense, Brave1 / EU4UA Defence Tech therefore remains an undertaking co-financed and politically legitimised by the European Union, but its contractual core – at least at the level of the relationship with the developer – has a clearly Ukrainian jurisdictional embedding. It is precisely this element that should close the analysis of the project level: Brave1 is not solely a mechanism for stimulating innovation, but also a system in which the Ukrainian state, through the innovation development fund and the contractual template, shapes the rules of access to technology, documentation and the results of R&D work. Thanks to this, the cluster can perform the function of a multiplier of mass and scale of production, but it does so in a formula which combines the retention of private intellectual property with a public safeguarding of informational and operational access. It is precisely this combination – and not the mere number of manufacturers – that explains why the dispersed market of FPV suppliers can be integrated into a single functional ecosystem of state-supported defence capability.[39]
3. The operational level
At the operational level, the basic source document is not a general political communication but the regulations of the grant programme, i.e. the Regulations for the Brave1 EU4UA Defence Tech Grant Program, made available in the Legal Terms section of the programme. It is precisely this document that constitutes the most useful source for practical analysis: it determines the framework of participation, the conditions of application, the function of grant support and the operational rules of the call within the initiative linked with EU4UA Defence Tech. In combination with the EEAS communication and the BRDO project description, this document creates the actual operational basis of the programme: the institutional communication legitimises the project and its financing by the EU, the project description indicates its purpose and place in the architecture of cooperation, while the grant regulations order the manner in which undertakings and technology teams can enter the support system. From the perspective of a legal report, it is precisely this operational layer that is key to understanding how dispersed manufacturers of FPV and other defence technologies have been gathered around a single cluster: not through an abstract political declaration, but through a set of specific procedures, grants, tests, validations and pathways to implementation. As a result, Brave1 operates as an institutional multiplier of production capability – it not only finances innovation but organises its transition into a mass state capability.[40]
The regulatory consequence of this scale is under-appreciated. Product certification regimes – both aviation and armaments – were built around the assumption of small-series production of goods with a long life cycle and high unit value. A model in which a platform comes into being within a week, is consumed within hours and undergoes continuous design modification in reaction to the adversary’s countermeasures is structurally incompatible with that assumption. No European conformity regime was designed for a product whose iteration cycle is shorter than the conformity assessment cycle.
That is precisely why the Ukrainian mass production of FPV should not be described solely as the result of wartime improvisation or of the cost advantage of a cheap platform over an expensive defensive effector, but also as the result of a consciously built institutional architecture in which Brave1 performs the function of a common node for the state, the military, grant-givers and the dispersed defence tech industry.[41]
The effectiveness of FPV depends on communications to a degree perhaps greater than on the quality of the platform itself, and the absolutely fundamental category here is the radio horizon. The radio horizon is not a separate normative concept of EU law or of Polish aviation law, but a technical-operational category describing the limit of effective propagation of a radio signal in communications requiring a line of sight between transmitter and receiver. In practice, this means that the range of control and data transmission depends not only on the power of the devices, but also on antenna height, terrain obstacles, built-up areas, forestation and the shape of the terrain. The legal significance of this category is therefore indirect in character: the concept itself is not regulated as a statutory definition, but the phenomena it describes enter legal analysis through the regime of radio equipment, spectrum management, electronic communications, and the safety and reliability requirements for unmanned operations, especially BVLOS and within U-space.[42]
The control signal and image transmission in classic FPV systems require as clean a line of sight as possible, which is why their propagation is attenuated not only by buildings, forest walls or dense development, but also by the relief of the terrain itself: depressions, escarpments, embankments, forested ridges, rural development and all obstacles that “break” the connection between the operator and the platform. In the realities of the Russo-Ukrainian war, this means that the advantage does not follow solely from the flight parameters of the drone, but from the ability to raise the communications point above terrain obstacles and to maintain a stable transmission channel despite jamming, masking and target movement. Hence the great importance acquired by relays – signal repeaters mounted on masts, on ground vehicles, and most often on separate drones hovering higher than the combat platform. In the simplest variant, such a relay is a separate item of equipment, a kind of “communications superstructure” added to the system; in more advanced solutions, the relay function becomes part of a larger architecture, in which one drone carries the payload, a second observes, a third provides retransmission, and further nodes take over part of the traffic in a network model. This means that the relay need not be understood solely as a single device purchased separately – increasingly it is a separate technological layer, which may take the form of a radio module, an additional aerial platform, a ground set, or a node in a mesh network. It is precisely here that one of the most interesting trends appears: the transition from a single repeater to a layered architecture, and then to dynamic mesh networks, in which every modem or selected platforms can simultaneously transmit and repeat the signal, creating a self-repairing chain of communications. In such an arrangement, the radio horizon problem is no longer solved by a single device, but by a system of systems, functionally approaching a swarm with a division of roles. This in turn means that the most valuable IP in this segment may not reside in the airframe at all, but in the signal-routing algorithms, node switching, jamming resistance, bandwidth management and the integration of the relay function with the combat or reconnaissance role. Competitive advantage may here be protected as a patent, software, a trade secret or systemic know-how; in practice, value increasingly shifts from “the drone itself” to the communications and control architecture which allows the platform to operate effectively outside the classic line of sight. In this sense, the fight for advantage in the air simultaneously becomes a fight over who will build a higher-elevated, more resilient and more intelligently managed transmission network than the adversary.
This architecture has legal significance extending beyond the battlefield. Retransmission is in essence the construction of an ad hoc, mobile radio communications network – and thus an activity which, in the civil regime, is subject to electronic communications law, spectrum management and the requirements of Directive 2014/53/EU on radio equipment. The civil equivalent of this architecture – relay networks for BVLOS operations – is one of the fundamental implementation challenges of the U-space framework.
RED 2014/53/EU – this is the radio equipment regime, i.e. not only “does the drone work”, but whether its communications modules:
The retransmission architecture has legal significance extending far beyond the battlefield, because from the civil perspective it in essence means the construction of an ad hoc, mobile electronic communications network for unmanned operations. What in wartime conditions takes the form of an improvised or semi-improvised radio bridge between operator and drone becomes, in the civil environment, a multi-layered issue: it concerns not only the aircraft itself, but also radio equipment, frequencies, electromagnetic compatibility, data integrity, network resilience and liability for the continuity of the communications service. For this reason, at least three legal orders enter here in parallel.[43] First, the law of electronic communications and spectrum management, because the relay is no longer merely “part of the drone”, but an element of transmission infrastructure affecting the radio spectrum and requiring conformity with the rules on the use of bands. Second, Directive 2014/53/EU (RED), i.e. the radio equipment regime, whose essence is to ensure that equipment uses the spectrum efficiently, does not interfere with the operation of other systems and satisfies safety and compatibility requirements. Third, the U-space framework, which is not “a single drone system” but a regulatory model of highly digitalised and partly automated management of a large number of unmanned operations, in particular also BVLOS (beyond visual line of sight) flights. Relay networks for BVLOS operations therefore in practice mean a model in which the continuity of the flight does not depend on a simple, linear operator-drone connection, but on an entire chain of communications services, identification, data transmission and coordination with the digital airspace. That is precisely why one of the main implementation challenges of U-space is not the mere fact that the drone flies beyond visual range, but who is responsible, and on what terms, for the communications layer sustaining such a flight: for the reliability of the channel, the interoperability of the equipment, information security, jamming resistance, cybersecurity and the technical conformity of the entire transmission chain. In civil conditions, the problem which at the front is solved by an improvised relay or a mesh network therefore becomes a regulatory problem of the highest rank: the question is no longer only whether the drone may fly, but whether there exists a lawful and secure communications infrastructure allowing it to fly outside the simple logic of direct contact.[44]
If, however, the relay and the mesh network[45] are an attempt to solve the radio horizon problem within the logic of radio emission, then fibre-optic drones represent an attempt to step outside that logic altogether. Whereas the relay architecture endeavours to elevate, stabilise and disperse the signal, the optical fibre eliminates the need for its emission in radio space, and thereby undermines a considerable part of the existing assumptions of both counter-drone technologies and regulation based on the detectability and jammability of the signal.
Mesh network, Shahed/Geran and the shift from loitering munition to a networked strike system
One of the most interesting and at the same time most disturbing phenomena of the current phase of the drone war is the transition from a simple point-to-point control model to a mesh network architecture, that is a lattice or grid network. Unlike the classic arrangement in which the operator communicates directly with a single platform or via a single relay, the mesh network consists of many nodes capable of simultaneously receiving, forwarding and amplifying the signal. Each such node can be part of a larger transmission system: a ground modem, an intermediate station, an observation platform or the drone itself. In practice, this means that communications do not depend on one channel and one transmission route, but can be dynamically reconfigured depending on which elements of the network remain active, where the platforms are located and what the jamming environment looks like. That is precisely why the mesh network is an architecture more resilient, flexible and difficult to disable than a classic linear connection. It is no longer a “link to the drone”, but a dispersed operational network.
In relation to heavy platforms of the Shahed/Geran type, such an architecture has breakthrough significance, because it blurs the boundary between a loitering munition and a network-controlled or network-supervised drone. Traditionally, loitering munitions are perceived as an essentially single-use means flying along a route programmed in advance or corrected to a limited extent. Meanwhile, equipping heavy drones with mesh modems, retransmission nodes and external relay points means that the system ceases to be merely a “blind carrier” executing a sequence of commands recorded once. It enters a more flexible model: it can maintain communications deeper over the adversary’s territory, benefit from mutual signal amplification, and in some configurations also from more up-to-date mission supervision. It is precisely for this reason that analysts speak of the blurring of the boundary between the classic loitering munition and the one-way attack UAV with elements of networked command. In other words: if the “Shahed” begins to function as part of a communications system, it ceases to be solely a single-use kinetic effect and begins to resemble a networked means of aerial attack, whose effectiveness depends not only on the airframe and warhead, but on the data transmission architecture.
This is very well illustrated by the Belarusian case from the beginning of 2026, when reports appeared in the analytical space of Russia’s use of relay stations and other network nodes supporting the flights of Shaheds operating from that direction, and subsequently of their elimination by the Ukrainian side.[46] Even if part of the details of those events remains based on front-line, technical and media sources rather than on full, open official material, the operational sense of such a solution is itself logical and coherent: if the platform is to fly deep, maintain communications and benefit from the effect of mutual retransmission, then the network cannot end at the drone itself. It must have external nodes sustaining the communications architecture, whether in the form of border stations, relay towers, ground amplification points or other supporting elements. The destruction of such nodes does not mean the destruction of a single drone, but a strike at the network layer which makes the entire system more dangerous. In this sense, Ukraine is not merely destroying the carrier of a warhead, but degrading the communications infrastructure of the attack.
Technologically, the most dangerous aspect is that the mesh network changes the logic of defence. In the classic model, it was enough to cut the connection, destroy the platform or jam a single channel. In the grid model, the adversary can attempt to:
This in turn naturally brings such a system closer to a swarm with a division of roles. Not all platforms have to attack. Some may perform the role of:
This means that advantage increasingly depends not on a “better drone” but on a better systemic architecture. It is precisely here that IP of the highest value is born: not in the airframe itself, but in the modems, transmission protocols, routing algorithms, jamming resistance, throughput management, node authorisation and the integration of the relay role with the combat role. Solutions of this kind may be protected as a patent, software, a trade secret or systemic know-how. In practice, market and military value therefore shifts from the individual product to the network architecture, which may be more difficult to copy than the drone itself.
This shift also has very significant legal consequences. First, the mesh network is not directly a legal category of aviation law or EU drone law; it is above all a technical concept. However, its legal significance is indirectly enormous, because it describes the structure of communications on which the operation of unmanned platforms depends. The moment such a network is analysed outside the theatre of hostilities, we immediately enter the area of electronic communications law, spectrum management and the radio equipment regime. For if the effectiveness of the drone depends on a dispersed arrangement of transmitters, modems and relay nodes, then we are no longer dealing solely with an aircraft, but with regulated communications infrastructure. Here, Directive 2014/53/EU (RED) gains significance, because all radio transmission modules – especially when they form a system of mutual relays – must be analysed from the perspective of the efficient use of the spectrum, electromagnetic compatibility and equipment safety. In such a framing, the mesh network is not only a technical feature but a question of whether the radio network being built conforms to the rules on the use of bands and does not generate new risks for other communications systems.
Second, the mesh network has a cybersecurity and information security dimension. Every additional node means not only greater flexibility of the communications architecture, but also a greater attack surface: more points vulnerable to takeover, impersonation of an authorised element of the system, spoofing, jamming or the injection of false data. The injection of false data should here be understood as the introduction into the network of signals, messages or parameters which appear authentic but are intended to mislead the other nodes, cause an erroneous reconfiguration of connections, direct the platforms along another route or distort the picture of the operational situation. The more the system passes from a simple point-to-point connection to a dispersed lattice network, the more crucial becomes not the mere transmission of the signal, but trust in its source, integrity and authenticity. That is precisely why mesh technology shifts the analysis from the level of simple drone control towards the issues of node authorisation, data integrity and the resilience of the communications architecture to manipulation.
The legal dimension of this phenomenon is multi-layered. First, the more the effectiveness of the system depends on a multi-node transmission architecture, the less sufficient it is to treat it solely as an aircraft, and the more necessary it becomes to conceive of it as an element of regulated radiocommunications infrastructure – and thus also through the prism of the radio equipment regime, spectrum use and electromagnetic compatibility, with which the significance of Directive 2014/53/EU (RED) is indirectly connected. Second, the strategic value of the system shifts from the airframe itself to the modems, antennas, amplifiers, jamming-resistance systems and routing software, which reinforces their significance as dual-use components. Third, the mesh architecture creates the conditions for dispersed functional autonomy: it enables the redirection of the flight during the mission, the use of other platforms as relays, the dynamic alteration of the communications structure and the combination of strike, reconnaissance and retransmission platforms into a single arrangement. In the case of heavy Shahed/Geran drones, this leads to the blurring of the boundary between the classic loitering munition and a network-supported means of aerial attack. The reports of the use of external relay stations on the Belarusian direction and of their elimination by the Ukrainian side show well that the object of the fight is now not only the drone itself, but also the communications layer which sustains its operation. In this sense, the drone war simultaneously becomes a war for control over dispersed data transmission infrastructure.
In a dispersed communications system, security no longer depends on a single link, but on the integrity of the entire arrangement of mutual trust between nodes. This makes the legal analysis of such systems naturally shift also towards questions of:
Third, mesh technology has an obvious significance for dual-use export control. While the airframe itself may be relatively simple, the true value and strategic sensitivity is concentrated in the communications components: modems, amplifiers, antennas, jamming-resistance systems, routing and network management software. It is precisely these elements that most easily move from the civil market to the military one and vice versa. In consequence, the components building mesh networks may be analysed not only as part of the end product, but as self-standing dual-use components, whose export, technical transfer and integration may be subject to a separate licensing and security assessment.
Fourth, the mesh network leads us to the boundary of the issues of AI and functional autonomy. The lattice network itself is not yet artificial intelligence, but when it begins to support:
then in practice we approach an architecture in which operational decisions no longer flow solely from a direct human command, but from the dispersed operation of the system. This gives rise to the classic questions of responsibility, predictability and the qualification of such a network as an element of a more autonomous means of warfare. In the European context, this tension is particularly interesting, because civil applications of AI and communications are subject to ever greater regulation, while military applications of networked autonomy remain to a large extent outside the scope of the classic civil conformity regimes.
Finally, from the perspective of the law of armed conflict, the mesh network changes the very object of what is regarded as a significant component of combat capability. If the effectiveness of the system depends on a dispersed layer of relays, modems and relay stations, then the target of military significance becomes not only the drone itself, but also the communications infrastructure sustaining its operation. This shifts the analysis from the level of the individual effector to the level of the entire network architecture. One might say that, in such a model, the drone war is becoming to an ever greater degree a war for control over the aerial and border-zone tactical internet.
The breakthrough proved to be drones controlled by optical fibre – a spool of thin glass fibre unwound in flight. The solution has its costs (the mass of the fibre limits range, payload and manoeuvrability), but it eliminates two problems at once: the radio horizon ceases to matter, and the drone cannot be jammed, because it emits no radio signal. It is an electronically “mute” platform – practically undetectable by RF detectors and resistant to electronic warfare.
Fibre-optic drones appeared en masse in August 2024 in the Kursk area,[47] where Russian platforms of this type – with a range of over 30 km and a “crystal-clear” image – paralysed Ukrainian logistics along the sole supply route. As one Ukrainian medic put it, logistics simply collapsed, because fibre-optic drones were monitoring all the routes. By January 2026, fibre-optic variants accounted in some sectors for 30–50% of Russian FPV operations and around 15% of Ukrainian ones. In 2025, countering fibre-optic drones became the central theme of the NATO Innovation Challenge.[48]
The regulatory significance of this category is difficult to overestimate and remains unnoticed in the public debate. The entire European acquis on countering unauthorised unmanned operations – both technical and normative – rests on the assumption that the drone emits a radio signal.[49] On this assumption were built the remote identification requirement, RF detection systems, the jamming powers granted to the services and, from June 2026, to critical infrastructure operators. The fibre-optic platform invalidates each of those mechanisms simultaneously. Regulation aimed at a specific relay technology ages faster than the legislative process in which it comes into being.
Classic jamming consists in generating noise on radio frequencies so that the drone cannot distinguish the operator’s signal from the interference and loses control. For platforms flying to preset coordinates (deep strike), spoofing is used instead – the substitution of the satellite navigation signal, as a result of which the drone “thinks” it is somewhere else and corrects its flight in the wrong direction.
This distinction translates directly into the choice of defensive means – but also into legal qualification. Jamming is an interference with the radio spectrum, and thus with a good administered by the state and protected by electronic communications provisions; spoofing is an interference with the integrity of the signal of a satellite navigation system,[50] and thus with infrastructure of a global character, the disruption of which has effects far beyond the target. The side effects of both measures – loss of the GNSS signal by civil aviation, maritime transport, power grids synchronised by satellite time – are a classic example of damage in which establishing the causal link and the responsible entity is exceptionally difficult. We return to this issue in section 4.3.
The category of loitering munitions deserves separate legal attention. It is a construction at the boundary between an unmanned aircraft and a missile: a platform which remains in the task area for an extended time, searching for a target, and then carries out the strike. The blurring of the boundary between “aircraft” and “munition” has consequences in each of the regimes analysed – from classification on the control list of dual-use items, through the intra-EU transfer regime, to the question of the character of human control over the use of force.
The highest tier consists of heavy long-range platforms. The model example is the Ukrainian FP-1. The Ukrainian FP-1,[57] developed by Fire Point, is a one-way strike drone of light construction,[58] including fuselage elements made of plywood, powered by a two-cylinder engine; industry and media sources estimate its unit cost at approximately USD 55,000–58,000, i.e. significantly below the level of comparable systems. In mid-2025, a rapid increase in the scale of production was reported, already counted in hundreds of units weekly and over 100 units daily, and in July 2026 drones attributed to the FP-1 family were linked to the strike on the refinery in Omsk, one of the deepest Ukrainian long-range attacks.[59]
This case study is instructive for three reasons. First, it shows the inversion of the classic cost curve of the defence industry: a construction made of commercially available materials achieves an operational effect comparable to systems of many times higher cost. Second, it demonstrates the scalability of production outside the traditional armaments chain – growth from 30 to over 100 units daily within a few months is difficult under the regime of classic military certification. Third, this problem illustrates that range is not solely a technical parameter, but also a regulatory category. This follows from the logic of the Missile Technology Control Regime (MTCR), which – although it is not a classic international agreement in treaty form, but an informal export control regime based on common guidelines and a control annex – has long covered not only classic missiles but also unmanned aerial systems capable of carrying a payload over considerable distances. The most restrictive layer, i.e. Category I, encompasses complete rocket systems and unmanned aerial systems capable of delivering a payload of at least 500 kg to a range of at least 300 km, together with specified subsystems and technologies. This means that a platform with a range exceeding 2,500 km – even if it does not always satisfy every historical parameter of a classic missile system – enters the same type of strategic regulatory sensitivity which for decades has triggered the sharpest logic of proliferation control. In European practice, this logic was subsequently absorbed into the dual-use regime, in which references to the MTCR remain an element of the system of control of exports of technology and means of delivery (in EU law, the logic of the Missile Technology Control Regime (MTCR) was taken over into the system of control of exports of dual-use items primarily by Regulation (EU) 2021/821, which in recital 3 refers to the multilateral export control regimes, including expressly the MTCR, and then develops this logic operationally in Annex I, containing the EU dual-use control list). In this sense, great range is not merely an engineering feature, but a legally relevant feature, because from a specified threshold it triggers a normative order closer to proliferation control, export control and strategic security than to the ordinary regulation of a civil UAV.[60]
The boundary between control and autonomy is blurring. Placing a satellite communications terminal on a drone allows it to be controlled from enormous distances; the use of machine vision algorithms enables autonomous terminal guidance onto the target after loss of communications.[61] It is precisely this last feature – terminal autonomy, i.e. the capability to complete the task without a human in the decision loop – that is the heart of the legal problem to which we now turn.
Conceptual precision, usually lacking in the public debate, is worth preserving here. Autonomy is not a binary feature but a spectrum encompassing at least: (i) flight stabilisation and route keeping, (ii) navigation without a satellite signal using terrain image correlation, (iii) automatic detection and classification of objects, (iv) automatic tracking of a target designated by the operator in the terminal phase, (v) independent selection of a target within a designated area. Legal regimes – both the EU Artificial Intelligence Act and the discussion of autonomous weapon systems within the framework of the CCW Convention – react differently to each of these levels, and the distinction between (iv) and (v) is in practice the most difficult to prove in evidentiary proceedings and at the same time the most legally momentous.[62]
Symmetrically to the strike layer, the countermeasure layer (_counter-UAS_, C-UAS) has developed, which for the European civil market today has greater economic significance than the strike layer itself. Its taxonomy comprises two segments.
Detection and identification: radio sensors (monitoring of control and image-transmission bands), low-power radars, acoustic sensors, optoelectronic systems with a thermal channel, and – increasingly – fusion of data from multiple sensors with machine-learning-based classification. It is precisely in this segment that artificial intelligence performs a critical role, and it is precisely this segment that is fully civil, and therefore covered by the EU regime without exclusions.
Neutralisation: jamming of the control link and image transmission, spoofing of satellite navigation, taking over control of the platform, mechanical means (nets, including those launched from interceptor platforms), kinetic means (from smoothbore weapons to artillery systems with programmable ammunition), directed energy (lasers, high-power pulse) and interceptor drones.
This distinction is legally significant, because each of the effectors is subject to a different regime: jamming and spoofing fall under electronic communications law and spectrum management; kinetic means fall under the law on weapons and ammunition and liability for damage caused by falling debris; taking over control is an interference with an ICT system, and thus potentially an act criminalised under criminal law if it does not have an express statutory basis. A separate problem is that effective detection requires data processing – on which see section 3.7.
For the legal analysis of autonomy, it is indispensable to break the process down into links. Adopting a simplified model of the kill chain: a) detection b) identification and classification c) prioritisation d) engagement decision e) terminal guidance f) effects assessment. The debate on “meaningful human control” in essence concerns the question in which of these links the human takes the constitutive decision and whether at that moment he has information and time sufficient for that decision to be real rather than formal in character.
In the practice of contemporary drone operations: the first and second links are increasingly automated (image classifiers), the fourth link remains on the human side, and the fifth link is sometimes autonomous out of technical necessity – after loss of the link. Legally, this means that the “human in the loop” construction rests on a link of which the adversary consistently tries to deprive it. The argument that loss of communications is a technical circumstance and not a design decision loses its force at the moment when the manufacturer designs the platform on the assumption of operation in a heavily jammed environment.
An analogous structure – with different consequences – occurs on the civil side. Article 14 of the Artificial Intelligence Act requires that a high-risk system be designed so that natural persons can effectively oversee it, including understanding its limitations, correctly interpreting its output and deciding not to use it or to interrupt its operation. This requirement is technically identical to the postulate of meaningful human control – with the difference that on the civil track it is a legal norm backed by a sanction, while on the military track it remains the subject of unfinished international negotiations.
The last layer, systematically omitted in technical analyses, is the data layer. Each of the platforms described is above all a sensor generating a stream of data: visual and thermal imagery, telemetry, position, radio spectrum parameters. The operational value of an unmanned system today lies to a lesser degree in the platform and to a greater degree in the chain of processing of those data – from transmission, through storage and annotation, to use in training image-recognition models.
From this arises a chain which crosses the civil-military boundary in both directions. Collections of recordings from combat operations constitute training material of a value impossible to obtain in laboratory conditions – and they are used to perfect classifiers, which subsequently find their way into civil systems (infrastructure monitoring, border protection, crisis management). In the other direction: models trained on civil collections of aerial imagery constitute the base for target-recognition systems.
This bidirectional flow is – as we demonstrate in section 4.5 – the area in which the EU data protection and artificial intelligence regimes come into contact with the defence exclusions in the manner that is legally most unclear and practically most momentous.
Drone warfare is a spiral process: each innovation provokes a countermeasure, and that forces the next innovation: the observation Mavic; drops; FPV; jamming; the relay; the optical fibre; satellite communications; satellite jamming; AI autonomy; interceptor drones.
For the regulator, this means that every norm aimed at a specific technology ages at the pace of that spiral. This is an argument in favour of regulation based on effects and on the level of risk, rather than on a catalogue of technical solutions – and at the same time an explanation of why acts based on risk classification (the Artificial Intelligence Act) have a greater chance of remaining current than acts based on product catalogues (dual-use control lists, classes C0–C6).
The legal environment of the UAV sector is not one act or one branch. It is a lattice of regimes, which it is worth ordering into nine pillars. Below, we furnish each of them both with its legal basis and with a practical “flavour” relevant to the servicing of entities in the sector.
The original version of this taxonomy comprised seven pillars. The extension by two further ones – personal data protection and data governance, and public international law – is not a tidying-up exercise. It follows from the observation made in section 2.10: since the value of the unmanned system has shifted from the platform to the data, the data regime has ceased to be a side issue and has become one of the two or three pillars determining the business model. International law, in turn, is the only regime which covers the space left by the defence exclusions of EU law – and therefore precisely the space in which the revolution described above is playing out.
The core of the civil regime is formed by three related acts founded on the basic Regulation (EU) 2018/1139 (EASA): Delegated Regulation (EU) 2019/945 (product requirements, classes C0–C6, CE marking) and Implementing Regulation (EU) 2019/947 (operations in the open, specific and certified categories). The spatial layer is completed by the U-space package: Implementing Regulation (EU) 2021/664 together with 2021/665 and 2021/666.
The architecture of this pillar rests on two independent axes of qualification, the confusion of which is the most frequent error in the practice of the industry. The first axis – the product axis – concerns what the device is: classes C0–C6 lay down construction requirements, including the obligation to be equipped with a remote identification system and a geo-awareness function for the higher classes. The second axis – the operational axis – concerns what is done with it: the open category covers low-risk operations within visual range, the specific category requires an authorisation based on a risk assessment (the SORA methodology) or a declaration of conformity with a standard scenario, and the certified category brings the regime close to classic manned aviation.
The U-space layer, in turn, introduces mandatory services in designated airspaces: network identification, geo-awareness, traffic information and flight authorisation, provided by certified service providers.
The practical dimension is therefore that the regime is not static. Regulation 2019/947 has applied in its consolidated version since 1 May 2025, and the U-space framework was reinforced by Regulation (EU) 2023/203, which added information security requirements – risk assessment, management and incident response. Of key interpretative importance is therefore the revision of the Easy Access Rules for UAS of June 2026, consolidating the AMC/GM to Regulation 2019/947 (ED Decision 2025/018/R). From 1 January 2026, flights in standard scenarios require platforms holding a class C5 or C6 certificate. In a broader perspective, this confirms that in the UAV sector law does not end with the text of the regulation itself, but also functions in the executive, interpretative and operational layer. It is precisely at this level – through the AMC, GM and their consolidation in the Easy Access Rules – that general norms are translated into compliance practice, risk assessment, operational documentation and the everyday application of the law by operators, manufacturers, advisers and supervisory authorities. As a result, an analysis of the legal environment of drones requires account to be taken not only of the formally binding provisions, but also of how they are operationalised in executive and interpretative materials, because it is only there that the real regulatory weight of the sector is revealed. AMC (Acceptable Means of Compliance) and GM (Guidance Material) do not have the character of independently binding provisions of the rank of a regulation, but they perform a fundamental interpretative and practical function: they show how entities can demonstrate conformity with the requirements arising from Regulation (EU) 2019/947 and how authorities and operators should understand the individual obligations in operational practice. That is precisely why the Easy Access Rules for Unmanned Aircraft Systems are of such great importance for the UAV sector – they do not create new law, but order, consolidate and operationalise the normative material and its interpretation, becoming in practice the basic working tool for operators, manufacturers, advisers and supervisory authorities.[63]
A systemic remark: this entire pillar concerns civil aviation exclusively. Article 2(3)(a) of Regulation 2018/1139 excludes from its scope of application aircraft carrying out military, customs, police, search and rescue, firefighting, border control and coastguard operations. The first and most far-reaching defence exclusion therefore appears already at the level of the foundation, and not only in the Artificial Intelligence Act. This means that the boundary between the civil and the defence order is drawn already in the EASA basic regulation itself: it is that regulation which determines that the development, certification and operation of military unmanned systems are not subject to the EU regime of common civil aviation rules, but remain within the domain of the competence of the Member States, their defence policies and the relevant national security regimes. From the perspective of an analysis of the UAV sector, this is of fundamental importance, because it shows that the dual-track nature of the regime does not begin at the stage of AI, autonomy or export control, but already at the level of the most basic question of whether a given aircraft is subject to common European aviation law at all. In practice, this means that identical or nearly identical technology may be covered by the full civil conformity regime if it functions on the commercial market, while at the same time remaining outside that regime if it is incorporated into a military operation or one directly connected with it.
Regulation (EU) 2024/1689 (the Artificial Intelligence Act, “AI Act”) introduces a risk-based classification: prohibited practices (Article 5), high-risk systems (Article 6 in conjunction with Annexes I and III), systems subject to transparency obligations (Article 50), general-purpose models (Articles 51–55) and the remainder, not covered by substantive obligations.
For the UAV sector, however, what is decisive is not what the act regulates, but what it does not regulate. Article 2(3) provides:
“This Regulation does not apply to AI systems where and in so far they are placed on the market, put into service, or used with or without modification exclusively for military, defence or national security purposes.” – Article 2(3) of Regulation (EU) 2024/1689.
The consequence is paradoxical: a civil drone with AI is subject to the full high-risk regime, while a technologically identical platform used “exclusively” for military purposes remains outside the scope. The criterion is not the technology, but the purpose of use. Lethal autonomous weapon systems (LAWS) therefore remain outside the EU regime; the matter is the subject of international law and NATO doctrines, and the European Parliament has repeatedly warned against the Union’s regulatory backwardness in this area. The European Parliament was one of the earliest institutional actors to take up the subject of autonomous weapon systems and military AI, adopting already in 2018 a resolution on LAWS, and then in 2021 a resolution relating to artificial intelligence in the military and civil context.[64]
Key, however, is the word “exclusively”. Recital 24 of the preamble specifies that if the system is also used for purposes other than military, defence or national security – even temporarily and even by another entity – the exclusion does not apply to that extent. For a dual-use manufacturer, this means that the exclusion is not a feature of the product, but a feature of the specific placing on the market or putting into service. The same product series sold simultaneously to a military purchaser and to a critical infrastructure operator is, in the second case, subject to the full regime – and the manufacturer must be able to document this duality, separate the product lines and demonstrate it in the event of an inspection.
In practice, the classification proceeds along two independent tracks:
The consequence of qualification is the set of obligations under Articles 8–15: a risk management system, data and data quality governance (Article 10), technical documentation (Article 11), automatic recording of events (Article 12), transparency and information for the user (Article 13), human oversight (Article 14) and accuracy, robustness and cybersecurity (Article 15) – and, on the procedural side: conformity assessment, the EU declaration, CE marking and registration in the EU database.
Market practice planned compliance for over a year around the date of 2 August 2026. That date has changed. On 19 November 2025, the Commission presented a simplification package (the Digital Omnibus), whose part concerning artificial intelligence – after the unsuccessful trilogue of 28 April 2026 and the political agreement of 6–7 May 2026 – was finally approved by the Council on 29 June 2026 (Parliament: 16 June 2026). The result is a postponement:
The postponement is conditional in character and is linked to a readiness mechanism: the registration of systems in the EU database and the availability of harmonised standards. The following, by contrast, apply unchanged: the prohibitions under Article 5 (from 2 February 2025), the AI literacy obligation under Article 4 (from 2 February 2025) and the general-purpose model regime (from 2 August 2025).[65]
In practice, the postponement is not a relief but a shift. The task which cannot be omitted or accelerated is the inventory of AI systems in the organisation and the assignment of each of them to the appropriate category – work independent of the state of the harmonised standards. In addition, the grandfathering principle applies: systems placed on the market before the date of application are not subject to the obligations until they are substantially modified – which, in a sector with an iteration cycle counted in weeks, is a guarantee of limited value.
Regulation (EU) 2021/821 establishes the Union’s system for the control of exports of dual-use items; it entered into force on 9 September 2021, replacing Regulation (EC) No 428/2009, and has applied in its consolidated version since 15 November 2025. On 8 September 2025,[66] the Commission updated Annex I (the control list), covering emerging technologies – which directly affects drone components, electronics and AI software.
Four mechanisms of this regime are significant for the unmanned sector:
1. The control list (Annex I) – drone components are dispersed across several categories: electronics (cat. 3), sensors and lasers (cat. 6), navigation and avionics (cat. 7) and aerospace and propulsion (cat. 9). Qualification rarely concerns the platform as a whole – most often a single subassembly is decisive.
2. Catch-all clauses (Article 4) – the obligation to obtain an authorisation arises also for items not included in the list, if the exporter has been informed or is aware of an intended use connected with weapons of mass destruction, military purposes in a state subject to an embargo, or parts for armaments exported without authorisation. This is the instrument which in practice covers the largest number of drone transactions, because it operates independently of the list.
3. Control of intangible technology transfer (ITT) – the regime covers not only things, but also software and technology, including making them available by electronic means. In practice, this means that granting remote access to a code repository, transferring model weights[67] or placing technical documentation in a cloud outside the customs territory of the Union may constitute an export requiring an authorisation.
4. Cyber-surveillance items (Article 5) – a control mechanism covering items not included in the list, intended for surveillance, where there is a risk of use for human rights violations; it applies directly to advanced observation systems and image analytics.
The complementary layer is formed by: Directive 2009/43/EC on intra-EU transfers of defence-related products (simplified within the framework of the Defence Readiness Omnibus), the international regimes (the Wassenaar Arrangement, the MTCR – whose Category I traditionally covers unmanned systems with specified range and payload parameters) and, at national level, the Act of 29 November 2000 on foreign trade in goods, technologies and services of strategic importance.
IMPORTANT for M&A practice: in the due diligence of an entity in the drone sector, the qualification of components as dual use determines the export authorisation regime, the end-user and re-export prohibition clauses and – in real terms – the feasibility of the cross-border transaction. The disappearance of the commercial/combat boundary (a mass-produced observation drone converted into a combat platform without design changes) makes this qualification ever broader, and the regulatory risk ever more difficult to price. Particular attention is required in the situation where the purchaser is an entity from outside the Union: the mere transfer of technical documentation in the company examination process may require an authorisation before the agreement is even concluded.
This is the pillar in which law performs the function of a driver. The EU instruments do not react to technology – they create demand, direct the stream of public funds and establish the framework for joint production and procurement:
• The European Defence Fund (EDF)[68] – co-financing of joint defence research and development projects, lowering the industry’s investment risk.
The superstructure of these instruments is the Defence Readiness Omnibus[73] of 17 June 2025 – a legislative and non-legislative package intended to remove administrative barriers to defence investment estimated at EUR 800 billion over a four-year perspective. It includes, inter alia, accelerated authorisation procedures for defence projects with a single point of contact, extension of the maximum duration of framework agreements to ten years, simplification of intra-EU transfers of defence products (where delays reached a year), clarification of the defence exclusions in chemicals legislation (REACH, CLP, biocidal products) and – which is particularly significant for financing – a communication clarifying the application of the sustainable finance framework to the defence sector. In June 2026, the co-legislators reached a preliminary agreement on the procurement part of the package, extending the increased EDF financing to actions carried out within the framework of SEAP and permitting the eligibility of the costs of tests conducted in Ukraine.
A separate, younger layer is formed by the four flagship projects[74] of the Readiness Roadmap 2030: the European Drone Defence Initiative, Eastern Flank Watch, the European Air Shield and the European Space Shield. EDDI – originally communicated as the “drone wall” – is to create a multi-layered network capable of detecting, tracking and neutralising hostile platforms, while preserving a dual-use dimension allowing civil applications (border protection, disaster response). The assumed timetable: launch in Q1 2026, initial capability by the end of 2026, full functionality by the end of 2027 (Eastern Flank Watch – by the end of 2028). They are complemented by the Action Plan on drone and counter-drone security of 11 February 2026 and the Drone Alliance with Ukraine, together with the announcement of the allocation of EUR 6 billion from the interest on immobilised Russian assets to support Ukrainian drone production.
The market confirms the direction: over a twelve-month horizon, autonomous drones attracted around USD 6.2 billion in 169 transactions, driving a 139-per-cent increase in defence robotics financing. Analysts at the same time point to the gap between the “battle-tested” Ukrainian ecosystem and the capital actually flowing in – a field in which legal advice and transaction structuring become critical.
The practical dimension: participation in the driver instruments has a legal price which must be factored in at the stage of structuring the consortium. The EDF and EDIP regimes contain extensive provisions on rights to the results of the project, access to existing knowledge (background) and generated knowledge (foreground), export restrictions on results and requirements of control over the entity (registered office in the Union, absence of third-country control or effective mechanisms for its limitation). For a company with capital from outside the Union, eligibility can be illusory if the ownership structure is not appropriately arranged in advance.
Regulation (EU) 2023/588 establishes the Union’s secure connectivity programme for 2023–2027 and the IRIS² constellation (Infrastructure for Resilience, Interconnectivity and Security by Satellite). It is the sovereign European answer to dependence on commercial satellite systems, whose role in the control of long-range drones was revealed by the conflict.[75]
Law here builds the physical layer on which the future generation of satellite-controlled platforms will rest – a classic infrastructural driver. The significance of this pillar is, however, deeper than technical: the experience of recent years has shown that a private satellite operator’s decision on coverage or on refusal to provide the service in a given area may have operational effects comparable to a decision of a state. The construction of a public capability is the answer to a problem which should be called the privatisation of communications sovereignty.
Since the first phase of the conflict was cyber warfare, the pillar of digital and physical resilience has systemic significance. It is formed by three acts of differing logic:
Both directive-form acts (NIS2, CER) require national transposition – which shifts the weight to the Polish level, discussed in Pillar IX.
The practical dimension: the convergence of the three regimes means that a manufacturer of a drone system for a critical infrastructure operator may simultaneously: (i) be subject to the CRA as a manufacturer of a product with digital elements, (ii) be an important entity within the meaning of NIS2 by virtue of its own manufacturing activity, and (iii) be covered by requirements arising from the obligations of its client under CER and NIS2, passed down contractually within the framework of supply chain risk management. Three regimes, three separate calendars, three separate sets of reporting obligations – while the event that triggers them is one.
This is a pillar systematically omitted in analyses of the defence sector, and at the same time the one which in practice most often blocks civil deployments. This follows from the observation made in section 2.10: the drone is above all a sensor, and a sensor turned towards the surface of the earth in an urbanised environment almost always records personal data.
Regulation (EU) 2016/679 (GDPR) applies to the processing of imagery from an unmanned platform on general principles, whereby in practice four issues are decisive:
For operations conducted by the services, the appropriate regime is Directive (EU) 2016/680 (the so-called Police Directive), transposed in Poland by the Act of 14 December 2018 on the protection of personal data processed in connection with the prevention and combating of crime.
A separate, younger layer is constituted by the governance of non-personal data. Regulation (EU) 2023/2854 (the Data Act), applicable from 12 September 2025, covers “connected products” – that is, devices generating data on their use and environment, to which unmanned systems belong directly. It imposes obligations to make data available to the user and to third parties designated by the user, and limits the freedom to shape contracts in this respect. Regulation (EU) 2022/868 (the Data Governance Act), in turn, creates the framework for the re-use of public sector data and data intermediation.
Finally, Article 10 of the Artificial Intelligence Act introduces quality requirements for the training, validation and testing data sets of high-risk systems – representativeness, relevance, examination for systematic errors. These requirements overlap with the GDPR regime in a manner which is sometimes a source of practical contradictions: the obligation to examine bias sometimes requires the processing of special-category data, the processing of which the GDPR as a rule prohibits. This issue is the subject of work on the data part of the Digital Omnibus.
Legislative status: in contrast to the part concerning artificial intelligence, the part of the simplification package covering the GDPR, the ePrivacy Directive, NIS2, the Data Act and DORA remains at the negotiation stage. At the end of June 2026, the Cypriot Presidency withdrew the compromise text from the approval procedure in COREPER II in the absence of a qualified majority; the file was taken over by the Irish Presidency. The European Data Protection Board and the European Data Protection Supervisor expressed, in Joint Opinion 2/2026 of 11 February 2026, decided opposition to the proposed narrowing of the definition of personal data. Until formal adoption, the existing state of the law applies – the contrary assumption is at this moment the most frequent error in compliance planning (The legislative status remains unclosed: in contrast to the part of the simplification package concerning artificial intelligence, the component covering the GDPR, privacy and electronic communications, NIS2, the Data Act and DORA still remains at the negotiation stage. It is officially known that the EDPB and the EDPS, in Joint Opinion 2/2026 of 11 February 2026, expressed substantial reservations about the proposed changes, including the narrowing of the definition of personal data. Expert sources further indicate that at the end of June 2026 the Cypriot Presidency withdrew the compromise text from the approval procedure in COREPER II in the absence of a qualified majority, which means that until formal adoption the existing state of the law continues to apply.[79]).
The space left by the defence exclusions of EU law is not a lawless space. It is filled – with varying effectiveness – by three regimes of international law.
International aviation law. The Chicago Convention of 1944 excludes state aircraft from its scope (Article 3), requires special authorisation for flights of pilotless aircraft over the territory of another state (Article 8) and – in Article 3 bis, added in 1984 – confirms the obligation to refrain from resorting to the use of weapons against civil aircraft in flight. This construction arose in a world in which the distinction “civil/state aircraft” was possible visually and procedurally. Applying it to an object with a wingspan of two metres, without markings, crossing the border unannounced, is a task for which the treaty was not designed.
International humanitarian law. The principles of distinction, proportionality and precautions in attack apply regardless of whether the decision on the use of force is taken by a human or assisted by an algorithm. Article 36 of Additional Protocol I of 1977 imposes on the parties the obligation to review new weapons, means and methods of warfare for their compatibility with international law – this provision is today the only universally binding instrument that covers autonomy in armaments, although it does so indirectly.[80]
The CCW process and the UN forum. The Group of Governmental Experts on lethal autonomous weapon systems (GGE on LAWS), operating since 2016 within the framework of the Convention on Prohibitions or Restrictions on the Use of Certain Conventional Weapons, has been working since 2024 on the so-called rolling text, encompassing elements of a potential instrument based on a two-tier approach of prohibitions and regulation. At the September 2025 session, a group of 42 states – one third of the parties to the Convention – declared readiness to move to negotiations on the basis of that text. On 6 November 2025, the UN General Assembly adopted, for the third time in succession, a resolution on autonomous weapon systems, supported by 156 states. The UN Secretary-General and the President of the International Committee of the Red Cross jointly called for the conclusion of negotiations on a legally binding instrument by the end of 2026. The Seventh CCW Review Conference, planned for November 2026, is the moment at which it will be decided whether a negotiating mandate will come into being – whereby the consensus rule applicable in that forum makes this outcome uncertain.[81]
The NATO layer comprises the principles of the responsible use of artificial intelligence in defence adopted in 2021 (lawfulness, accountability, explainability and traceability, reliability, governability, bias mitigation) and the revised AI strategy. These are not legally binding norms, but they constitute a point of reference for contractual requirements in allied procurement – and in this sense they affect industry more strongly than many a legal act.[82]
The Polish regime combines directly applicable EU regulations with national statutes and operational provisions. The Regulations (2019/945, 2019/947, 2021/664, 2021/821, 2023/588, 2024/1689, 2024/2847) apply directly; the directives (NIS2, CER) require transposition.
The aviation layer. The national basis is formed by the Act of 3 July 2002 – Aviation Law, substantially amended by the Act of 24 January 2025, which entered into force on 27 February 2025. The amendment adapted national law to the EU regime and introduced, inter alia: a register of operators of unmanned systems (a registration obligation for platforms of at least 250 g and – regardless of mass – those equipped with sensors capable of collecting personal data), the statutory empowerment of the Polish Air Navigation Services Agency to designate geographical zones, the extension of the catalogue of services entitled to check pilots, the lowering of the minimum age of a pilot in the open category from 16 to 14 under supervision, and a chapter devoted to the prevention of the unlawful performance of operations with the use of unmanned systems. Notification of the intention to perform an operation takes place through the DroneTower application, integrated with the PANSA UTM system and the National Drone Information System (KSID). The legal basis for the neutralisation of a platform remains Article 156ze of the Aviation Law (destruction, immobilisation or taking over control of the flight), supplemented by the provisions of the chapter on the prevention of unlawful operations.
Institutionally, this layer is completed by the Act of 8 December 2006 on the Polish Air Navigation Services Agency (Journal of Laws of 2025, item 1267), extended by the Agency’s competences in the area of unmanned systems, including the possibility of providing services to operators, supporting the testing of new solutions and creating special-purpose companies. Supervision is exercised by the President of the Civil Aviation Authority.
The resilience and countermeasure layer. The breakthrough is the Act of 29 May 2026 amending the Act on Crisis Management and certain other acts (Journal of Laws of 2026, item 815), implementing the CER Directive. Its significance for the sector under discussion extends far beyond its declared purpose:
The defence layer. It is formed by the Act of 11 March 2022 on the Defence of the Homeland – the national framework for the acquisition and operation of unmanned and counter-drone systems, together with the procurement regime in the fields of defence and security.
The direction of change. This area is evolving intensively in the years 2024–2026 and requires ongoing verification of the entries in the Journal of Laws and of legislative drafts. After a period of tightening of administrative sanctions, assessed by the operator community as disproportionate, the Civil Aviation Authority transmitted to the Ministry of Infrastructure on 5 May 2026 a draft amendment of a deregulatory and ordering character, covering the system of penalties, insurance, mandatory notifications, the securing of critical infrastructure and counter-drone systems. Entry into force is announced for the turn of 2026 and 2027. In parallel, work is under way on the full transposition of NIS2 within the framework of the amendment of the Act on the National Cybersecurity System.[83]
The pillars described in Part 3 do not form a coherent system. They come into contact with one another at points where their assumptions are mutually contradictory, and the resolution of the collision does not follow from any of them. It is precisely at these points that the undertaking’s real legal risk is concentrated – and it is they, not the content of the individual acts, that should set the agenda of legal advice.
The exclusion in Article 2(3) of the Artificial Intelligence Act operates on the condition of the exclusivity of the military, defence or national security purpose. This construction assumes that the purpose can be unambiguously assigned to the placing on the market or the putting into service. In the dual-use sector, this assumption is empirically false: the same machine vision module may be sold to the manufacturer of a power plant perimeter protection system and at the same time integrated into a military platform.
The practical consequences are three. First, the burden of demonstrating exclusivity rests on the entity that invokes it – and demonstrating a negative fact (the absence of civil application) requires documented control of the distribution channel and end-user clauses. Second, the exclusion relates to the system, not to the undertaking: a company may simultaneously be a provider of a high-risk system and a provider of an excluded system. Third, modification of the intended purpose after placing on the market changes the regime – and in a sector in which the end user routinely modifies the platform, this is a real risk, not a hypothetical one.
The practical recommendation is unambiguous: the separation of product lines at the documentary, contractual and – as far as possible – technical level, before the first mixed contract comes into being. Untangling this situation later is costly, and in the course of a company examination it is sometimes impracticable.
Article 14 of the Artificial Intelligence Act and the postulate of meaningful human control in humanitarian law[84] describe the same property of a system – the human’s capability to understand, verify and interrupt the operation of the automaton – but have an entirely different normative status. On the civil side, it is a legal obligation with an administrative sanction and a documentation requirement. On the military side – the subject of unfinished negotiations.
From this arises an asymmetry with industrial effects: a manufacturer that builds one technical platform for both tracks must design to the stricter requirement, because it cannot foresee in advance in which track a given unit will end up. Consequently, the civil requirement becomes the de facto design standard also for excluded applications – a mechanism worth calling the standard-transfer effect. This is one of the few situations in which the defence exclusion operates to the benefit, rather than to the detriment, of the coherence of the system.
The converse mechanism is, however, equally real: operational pressure to shorten the decision chain in a heavily jammed environment leads to constructions in which human oversight is formally preserved but in fact illusory – the operator approves a decision which he had neither the time nor the data to assess. Demonstrating such a situation in evidentiary proceedings requires access to event logs, which Article 12 of the Artificial Intelligence Act requires only on the civil side.
The jamming power, granted in Poland to critical infrastructure operators from June 2026, is an example of a norm which solves one problem and opens three further ones.[85]
Jamming devices are, as a rule, inadmissible for marketing and use: they do not satisfy the essential requirements of Directive 2014/53/EU on radio equipment (harmful interference), and their use violates the spectrum management regime. The grant of a statutory power removes the unlawfulness of the act itself, but does not settle liability for side effects. Interference in the bands used by satellite navigation systems affects civil aviation, transport, telecommunications networks and – which is sometimes overlooked – energy infrastructure synchronised by satellite time. Questions therefore arise as to: (i) the compensation liability regime of the facility operator towards third parties, (ii) the delimitation of liability between the operator and the manufacturer of the device, (iii) the documentation obligations allowing the course of the event to be reconstructed.
To this is added a third problem, described in section 2.4: the legal measure was granted at the moment when the technology against which it is effective is in retreat. The fibre-optic platform is resistant to jamming by definition. The norm responds to the state of the art of two years ago.
Shooting down or immobilising a platform does not end the event – it begins the fall of a mass with kinetic energy over terrain which is usually precisely what was to be protected. Polish law provides a basis for neutralisation (Article 156ze of the Aviation Law, the provisions of the chapter on the prevention of unlawful operations, the new powers under the Act of 29 May 2026), but the regime of liability for damage caused as a result of lawful neutralisation remains dispersed between the liability of the State Treasury for acts of public authority, the general rules of tortious liability and the special provisions on damage caused by the movement of aircraft.
A separate issue is the qualification of independent neutralisation by an unauthorised entity. The shooting down of a drone by the owner of the property over which it is flying is not the exercise of the right of ownership – it is the destruction of another’s thing and, depending on the circumstances, the creation of a danger. Judicial practice in this area is already taking shape.
This is the most under-defined point of the entire map. Collections of recordings from combat operations – visual and thermal imagery from thousands of sorties – have a training value unattainable in laboratory conditions. They flow, formally and informally, in both directions across the civil-military boundary.
The legal issues arrange themselves in three layers. Data protection: material of this kind contains the images of natural persons; processing in the course of hostilities falls within the exclusion of Article 2(2) GDPR, but the use of the same collection by a commercial entity to train a model intended for the civil market no longer does – and determining the moment at which the data “enter” the scope of application of the regulation has no unambiguous normative answer. Data quality: Article 10 of the Artificial Intelligence Act requires that the training data sets of high-risk systems be representative and free of systematic errors; a collection originating from one theatre of operations, one season of the year and one type of terrain does not satisfy that requirement, which has a direct bearing on the reliability of classifiers in civil applications. Export control: the weights of a model trained on such a collection may constitute controlled technology, and making them available outside the customs territory of the Union – an export requiring authorisation (cf. section 3.3, point 3).
The practical recommendation: in every transaction concerning an entity possessing vision models, the provenance of the training data sets must be established and documented in a manner allowing the lawfulness of the chain to be demonstrated. This is today one of the most frequently omitted – and most difficult to repair after the fact – elements of a company examination.
The export control regime is not limited to the physical movement of goods across the border. Within the meaning of Regulation (EU) 2021/821, “export” also includes the transmission of software or technology by electronic means – inter alia electronic mail, telephone or other electronic means – to a destination outside the customs territory of the Union. Making such software or technology available in electronic form to natural or legal persons located outside the customs territory of the Union is also deemed to be an export. In consequence, granting a foreign engineer, consultant or potential investor the ability to download controlled files from a repository may constitute an export, even if the data at all times remain saved on the same server and the access was remote and short-lived.[86]
This does not, however, mean that every making available of source code outside the Union automatically requires an authorisation. It must first be established whether the software or technical information in question has been included in the list of dual-use items in Annex I to Regulation 2021/821, or whether the conditions for the control of unlisted items are met on account of their intended end use or end user. In the unmanned aircraft sector, this assessment may concern both the design of the drone itself, its subassemblies and equipment, and the dedicated software and the technology necessary for their development, production or use. Potentially significant will be, inter alia, design documentation, aerodynamic models and simulations, control system diagrams, autopilot code, solutions concerning autonomous navigation, sensor integration, encrypted communications or jamming resistance. The classification should, however, refer to the parameters and criteria of the specific control entry, and not solely to the fact that the given technology is connected with drones.
The risk of intangible technology transfer arises above all in three configurations: (i) in a geographically dispersed development team including persons working from third countries; (ii) in the due diligence process, if the advisers or technical experts of a potential purchaser from outside the Union receive access to the repository, the design documentation or the test environment; and (iii) in the use of cloud infrastructure, if the data are transmitted to servers located outside the Union or can be accessed from there. The mere decentralisation of infrastructure, the use of blockchain technology or the storage of data in the cloud do not yet determine the occurrence of a controlled export. What matters above all is the content of the data, their export classification, the location of the recipient and whether the entity from outside the Union has obtained a real possibility of acquainting itself with the controlled technology. In the case of dispersed data storage, an additional problem may be the impossibility of reliably establishing in which states the individual nodes or copies of the data are located.
For this reason, control of access to repositories containing drone technologies should be an element of the internal export compliance programme, and not solely a cybersecurity procedure. Such a system should encompass the classification of repositories and documentation, the establishment of the state from which the user actually obtains access, the verification of end users and of the purpose of use of the technology, the segmentation of projects, the principle of least privilege, restrictions on the downloading and copying of files, and the keeping of access logs. For the protection of data against unauthorised access does not itself replace the answer to a separate regulatory question: whether the access of a person who is authorised, but located outside the Union, constitutes an export requiring an authorisation.
The last point of friction is the tension between strategic autonomy and the structure of the component market. The ecosystem which made possible the cost revolution described in section 2.2 rests to a considerable extent on components of geographically concentrated origin – from cells and motors to integrated circuits and cameras. The policy of reducing dependence collides with the fact that alternative European chains do not exist at a scale corresponding to demand.
Legally, this tension materialises in three instruments: the eligibility mechanisms in the financing programmes (the requirement of component origin and of control over the contractor), Regulation (EU) 2019/452 on the screening of foreign direct investments together with the national Act of 24 July 2015 on the control of certain investments,[87] and the sanctions regime. For an investor, this means that a transaction in this sector requires a parallel analysis of three consent paths: merger control, investment control and – where the object comprises listed assets – export consents. The transaction timetable must take this into account from day one; the attempt to catch up on these consents after the signing of the preliminary agreement is a typical cause of the failure of the process.
The juxtaposition of the nine pillars leads to the conclusion that law simultaneously performs three different roles – depending on the track in which we find ourselves – and leaves one area uncovered.
| Role of law | Pillars | Mechanism |
| Consequence of need | UAV/EASA, U-space level (civil track) | National law chases technology outpaced by the conflict; it regulates ex post what has already come into being |
| Driver | EDF, EDIRPA, ASAP, SAFE EDIP/SEAP, Defence Readiness Omnibus, IRIS², EDDI | Law creates demand, finances development, builds infrastructure and removes administrative barriers |
| Dampener | AI Act (civil track), dual use 2021/821, NIS2/CER/CRA, GDPR and the Data Act | Law limits the risk of mass dissemination, conditioning access to the market |
| Regulatory gap | LAWS / military AI, Art. 2(3) AI Act, art. 2 (2) GDPR, art. 2(3) (a) Reg. 2018/1139) | The defence exclusions leave development without a brake; international law fills this space only partially |
Law is neither exclusively a consequence nor exclusively a driver – it is dual-track. On the civil track it operates as a consequence of need and as a dampener; on the defence track as a driver. The mechanism separating the two tracks is the military exclusion in Article 2(3) of the Artificial Intelligence Act and the analogous defence exclusions in successive acts – whereby, as we demonstrated in section 3.1, the first of them appears already in the EASA basic regulation, and thus at the level of the foundation of the entire regime, not as a special exception.
The paradox lies in the fact that the same technology is simultaneously being accelerated on the defence side and dampened on the civil side – and the dual-use boundary along which this division runs is increasingly indistinct. What is more, in the years 2025–2026 we observe an additional phenomenon, which is worth noting as a fourth mechanism: simplification as a tool of industrial policy. Both the Defence Readiness Omnibus and the Digital Omnibus aim to lower regulatory burdens – the first on the defence track, the second on the civil one. The direction is convergent, the justifications different: in the first case defence readiness, in the second competitiveness. The effect is a convergence of the two tracks on the procedural side, while their substantive separateness is preserved.
For a client from the UAV sector, one question is key: on which side of the boundary – dual use, military/civil – is its product or project located. This qualification determines the entire legal regime that covers it. In practice, it is worth conducting it sequentially:
1. Is the product intended exclusively for military, defence or national security purposes? If so – the basis of that assertion and the mechanisms of control over the distribution channel must be documented. If not, or not fully – the civil regime applies in its entirety.
2. Does the Artificial Intelligence Act apply, and if so, on which basis? Annex I (a safety component of a certified product) or Annex III (critical infrastructure, law enforcement, borders)? On this depends not only the scope of the obligations, but also the date of their application (2 December 2027 or 2 August 2028).
3. Which product class and operational category does the platform concern under the 2019/945 and 2019/947 regime – and do the operations require an authorisation in the specific category?
4. Is the product or any of its components subject to export control on the basis of Regulation (EU) 2021/821 and the current control list, including under the regime of the catch-all clauses and intangible technology transfer?
5. Does the device process personal data – and if so, has an impact assessment been carried out and is the legal basis of the processing documented? Is the platform a “connected product” within the meaning of the Data Act?
6. What cybersecurity obligations (the CRA as manufacturer, NIS2 by virtue of its own activity, CER indirectly through the client) cover the manufacturer and the operator?
7. Does the project qualify for driver financing (EDF, EDIRPA, ASAP, SAFE, EDIP/SEAP) – and does the ownership and consortium structure satisfy the eligibility and control requirements?
In M&A practice, this means that the examination of the company must cover not only the classic areas (legal title to intellectual property, contracts, obligations), but also regulatory positioning. The checklist covers at least:
A procedural remark of significant practical importance: the mere conduct of the company examination may trigger export obligations if access to the technical documentation is obtained by advisers from third countries. The sequence of steps in the transaction process is therefore not a matter of convenience – it is an element of compliance.
| Date | Event |
| 2 August 2026 | Transparency obligations under Article 50 of the Artificial Intelligence Act (unchanged despite the simplification package) |
| September 2026 | Manufacturers’ reporting obligations under the Cyber Resilience Act |
| November 2026 | The Seventh CCW Review Conference – decision on the negotiating mandate concerning autonomous weapon systems |
| 2 December 2026 | Article 50(2) of the AI Act in relation to systems already present on the market; the new prohibitions under Article 5 |
| end of 2026 | Initial capability of the European Drone Defence Initiative and Eastern Flank Watch |
| turn of 2026/2027 | Announced entry into force of the Polish deregulatory amendment of the Aviation Law |
| end of 2027 | Full functionality of EDDI |
| 2 December 2027 | Obligations for standalone high-risk systems (Annex III of the AI Act) |
| December 2027 | Full application of the Cyber Resilience Act |
| 2 August 2028 | Obligations for AI embedded in regulated products (Annex I – including unmanned systems) |
| end of 2028 | Full functionality of Eastern Flank Watch |
The dates concerning the part of the simplification package relating to the GDPR, privacy in electronic communications, NIS2 and the Data Act remain unsettled – the file is in negotiations in the Council, and adoption before the end of 2026 is uncertain.
The postponement of the obligations for high-risk systems is sometimes read as consent to suspend work. This is an error with a measurable cost. Three tasks have no temporal alternative:
It is precisely here – at the interface of technology and the ever-denser lattice of regimes – that the added value of legal advice specialised in highly regulated sectors lies.
The Ukrainian conflict is a lens in which the future of dual-use technology can be seen, and a barometer of the direction of its regulation. It refutes the popular thesis that law by its nature restrains technological development: on the defence track, the legal layer of public financing has proved to be a vector of abrupt acceleration – and the instruments adopted in the years 2025–2026, from the Defence Readiness Omnibus to the flagship projects of the Readiness Roadmap 2030, are proof of this on a scale hitherto unknown in Europe. At the same time, it shows that as drones become widespread, civil law assumes a dampening function – controlling export, autonomy, data processing and access to airspace.
Three observations seem most significant for the further discussion.
First, the defence exclusions are not an exception to the rule, but a systemic construction repeated at every level of regulation – from the EASA basic regulation, through the GDPR, to the Artificial Intelligence Act. Each time, however, they have differently drawn boundaries, which means that the same platform may simultaneously be excluded from one regime and covered by another. The ordering of those boundaries is a task which the EU legislator has not yet undertaken.
Second, with the shift of value from the platform to the data and models, the regulatory weight is shifting from aviation law towards data and artificial intelligence law. A manufacturer that in 2019 needed mainly a certificate needs, in 2026, a documented chain of provenance of the training data sets, a vulnerability management system and jurisdiction-based access control.
Third, the innovation spiral will not slow down – and with it, the pace of the layering of the law will not slow down either. A norm responding to the state of the art of two years ago, adopted in reaction to an incident of a year ago, entering into force in a year’s time, will at the moment of its application relate to a world that no longer exists. This is an argument not against regulation, but for regulation based on effects and on the level of risk, resistant to a change of technical solution.
For lawyers serving this sector, the conclusion is one: an effective legal strategy begins with the conscious positioning of the product on the right side of each of the boundaries of the regime – and there are today nine of those boundaries, not one. The ability to move simultaneously in the technological and regulatory layer ceases to be an advantage and becomes a condition of presence on this market.
| Term | Meaning |
| BSP / UAS / UAV | Unmanned aircraft; an unmanned aircraft system also includes the control station and the link |
| FPV (first person view) | Control from a first-person perspective, through goggles receiving the image from the on-board camera |
| BVLOS | An operation beyond the operator’s visual line of sight |
| ISR | Intelligence, surveillance and reconnaissance |
| Relay | A repeater of the control signal and imagery, allowing terrain obstacles to be bypassed |
| Radio horizon | The maximum range of signal propagation limited by terrain relief and obstacles |
| Jamming | Emission of noise on the control frequencies with the aim of severing the link |
| Spoofing | Substitution of the satellite navigation signal, causing an erroneous determination of position |
| WRE / EW | Electronic warfare |
| Loitering munition | A platform remaining in the task area and carrying out a strike after detecting a target |
| Deep strike | A strike on targets located deep in the adversary’s territory |
| Terminal autonomy | The platform’s capability to complete the task without communications with the operator |
| C-UAS | Counter-unmanned aircraft systems |
| SBOM | A software bill of materials, required by the Cyber Resilience Act |
| U-space | A set of digital services enabling safe UAV operations in designated airspace |
| SORA | The risk assessment methodology for operations in the specific category |
KG Legal Kiełtyka Gładkowski. Partnership – Attorneys law firm advises entities from the high-technology sectors and highly regulated industries.
Attorney-at-law (radca prawny) Kazimierz Jakub Gładkowski specialises in corporate matters.
Attorney-at-law (radca prawny) Małgorzata Kiełtyka, entitled to appear before all courts, specialises in M&A transactions for entities from the high-technology and highly regulated sectors.
This article is of an informational and popular-science nature; it does not constitute legal advice. In individual matters, we recommend contacting the firm.
Additional Footnotes and Sources
1. Violations of Polish airspace on 9/10 September 2025 and earlier incidents (Romania – January 2025; Osiny – August 2025); launch of NATO’s operation Eastern Sentry; compare: T. Withington, “Europe’s Drone Wall – Ready, EDDI, Go!”, European Security & Defence, 13 March 2026, pp. 38–41; https://euro-sd.com/2026/03/articles/exclusive/49854/europes-drone-wall-ready-eddi-go/
2. Expert estimate concerning the pace of development of unmanned technologies in wartime conditions; cf. the analysis systematising drone warfare technology – M. Strzyżewski, “Anti-drone defense – shotguns, nets, EW, interceptor drones”, Marcin Strzyżewski YouTube channel, 2026 (video material).
3. The analogy and taxonomy of drone categories and the role of situational awareness; the persistence of commercial observation platforms on the battlefield after: M. Strzyżewski, op. cit.
4. “FPV Drone Warfare: The $1,000 Revolution Reshaping Modern Combat”, drone-warfare.com, 2026. https://drone-warfare.com/research/fpv-drone-warfare
5. V. Sutea, “Fiber-optic drones have emerged as critical kit for both Russia and Ukraine”, Atlantic Council – UkraineAlert, 24 February 2026 (the appearance of fibre-optic drones in August 2024 in the Kursk area; range of over 30 km, no susceptibility to jamming); https://www.atlanticcouncil.org/blogs/ukrainealert/fiber-optics-drones-have-emerged-as-critical-kit-for-both-russia-and-ukraine
6. NATO Allied Command Transformation, Innovation Challenge devoted to countering fibre-optic drones, 2025 – cf. Atlantic Council, op. cit.
7. “Fire Point FP-1”, Wikipedia (as at 21 July 2026); cf. “FP-1 vs Shahed: Ukraine Ramps Up Production…”, United24 Media, 20 August 2025 (unit cost approx. USD 55 thousand; plywood fuselage, two-cylinder engine).
8. “Russian largest oil refinery hit for first time by Ukrainian drones”, Politico Europe, 6 July 2026; cf. Tom’s Hardware, 17 July 2026 (strike on the Omsk refinery after a flight of over 2,500 km). https://www.tomshardware.com/tech-industry/drones/ukraines-55000-plywood-drone-flew-2500-km-and-shut-down-russias-largest-oil-refinery
9. Regulation (EU) 2018/1139 (EASA), including Article 2(3)(a) (exclusion of military, customs, police and related operations); Delegated Regulation (EU) 2019/945; Implementing Regulation (EU) 2019/947 (open / specific / certified categories). Source: EUR-Lex.
10. Implementing Regulation (EU) 2021/664 (the U-space framework) together with 2021/665 and 2021/666. Source: EUR-Lex; EASA.
11. Regulation (EU) 2023/203 (information security requirements in U-space); the consolidated version of 2019/947 applicable from 1 May 2025. Source: EUR-Lex; SKYbrary.
12. EASA, Easy Access Rules for Unmanned Aircraft Systems – revision of June 2026 (consolidation of the AMC/GM to 2019/947, ED Decision 2025/018/R).
13. Regulation (EU) 2024/1689 (the Artificial Intelligence Act), Article 2(3) and recital 24; Articles 4, 5, 6, 8–15, 50, 51–55; Annexes I and III. Source: EUR-Lex; artificialintelligenceact.eu (Article 2: Scope).
14. European Parliament, EPRS, “Defence and artificial intelligence”, 2025 (LAWS outside the scope of the AI Act by virtue of Article 2(3); calls for international regulation).
15. Digital Omnibus on AI: Commission proposal of 19 November 2025; unsuccessful trilogue of 28 April 2026; preliminary political agreement of 6–7 May 2026; confirmation by Member State representatives on 13 May 2026; approval by the Parliament on 16 June 2026 and by the Council on 29 June 2026. New dates: 2 December 2027 (Annex III), 2 August 2028 (Annex I), 2 December 2026 (Article 50(2) in relation to existing systems and the new prohibitions). Cf. analyses: Gibson Dunn, May 2026; Travers Smith, May 2026.
16. Regulation (EU) 2021/821 (dual-use export control); entry into force on 9 September 2021; consolidated version from 15 November 2025; Article 4 (catch-all clauses), Article 5 (cyber-surveillance items), the intangible technology transfer regime. Source: EUR-Lex.
17. European Commission, update of Annex I to Regulation (EU) 2021/821 of 8 September 2025 (emerging technologies). Cf. Akin, “EU Updates Dual-Use Export Control List”, 16 September 2025.
18. Directive 2009/43/EC on intra-EU transfers of defence-related products; the Act of 29 November 2000 on foreign trade in goods, technologies and services of strategic importance.
19. Regulation (EU) 2023/2418 (EDIRPA – common defence procurement). Source: EUR-Lex; European Commission (DG DEFIS).
20. The SAFE instrument (Security Action for Europe), 2025; procurement to be carried out by the end of 2030. Cf. European Parliament, EPRS, “EU joint defence procurement”, 2026.
21. Defence Readiness Omnibus, European Commission, 17 June 2025 (accelerated authorisations, framework agreements up to 10 years, simplification of intra-EU transfers, exclusions in REACH/CLP, communication on sustainable finance); preliminary agreement of the co-legislators on the procurement part, June 2026. Source: European Commission (DG DEFIS); Staff Working Document to the proposal of 17 June 2025.
22. Readiness Roadmap 2030 and the four flagship projects: European Drone Defence Initiative, Eastern Flank Watch, European Air Shield, European Space Shield; timetable: launch Q1 2026, initial capability end of 2026, full functionality of EDDI end of 2027, Eastern Flank Watch end of 2028. Source: European Commission (DG DEFIS); European Parliament, EPRS, “Eastern Flank Watch and European Drone Wall”, October 2025.
23. European Commission, Action Plan on drone and counter-drone security, 11 February 2026 (IP/26/364); Drone Alliance with Ukraine; announcement of the allocation of EUR 6 billion from the interest on immobilised Russian assets.
24. “Drone deals fueled VC’s 139% surge into defense robotics”, PitchBook, 19 March 2026 (approx. USD 6.2 billion in 169 transactions; a 139% increase).
25. “Ukraine 2025 defence tech investment topped $57.2M, but the ‘funded market’ is $6.8B, says PitchBook”, Resilience Media, 9 July 2026.
26. Regulation (EU) 2023/588 (the secure connectivity programme 2023–2027; the IRIS constellation). Source: EUR-Lex; European Commission (DG DEFIS).
27. Directive (EU) 2022/2555 (NIS2), repealing Directive 2016/1148. Source: EUR-Lex; European Commission (DG CNECT).
28. Directive (EU) 2022/2557 (CER – resilience of critical entities). Source: EUR-Lex.
29. Regulation (EU) 2024/2847 (the Cyber Resilience Act) – reporting obligations from September 2026, full application from December 2027. Source: EUR-Lex.
30. Regulation (EU) 2016/679 (GDPR), Article 2(2)(a) and (b), Articles 5, 6, 9, 13–14, 35; Article 4(2) TEU. European Data Protection Board, Guidelines 3/2019 on the processing of personal data through video devices. Directive (EU) 2016/680 and the Act of 14 December 2018 on the protection of personal data processed in connection with the prevention and combating of crime.
31. Regulation (EU) 2023/2854 (the Data Act), applicable from 12 September 2025; Regulation (EU) 2022/868 (the Data Governance Act).
32. The Digital Omnibus – the data part (GDPR, privacy in electronic communications, NIS2, the Data Act, DORA): negotiating status as at July 2026; withdrawal of the Cypriot Presidency’s compromise text from the COREPER II procedure at the end of June 2026. EDPB and EDPS, Joint Opinion 2/2026 of 11 February 2026 (opposition to the narrowing of the definition of personal data); Joint Opinion 1/2026 of 20 January 2026 on the amendments to the Artificial Intelligence Act.
33. The Convention on International Civil Aviation (Chicago, 1944), Articles 3, 3 bis and 8; Additional Protocol I to the Geneva Conventions (1977), Article 36.
34. The Group of Governmental Experts on LAWS within the framework of the CCW Convention: rolling text since 2024; joint statement of 42 states, September 2025; resolution of the First Committee of the UN General Assembly of 6 November 2025 (156 states); joint call of the UN Secretary-General and the President of the ICRC for the conclusion of negotiations by the end of 2026; Seventh CCW Review Conference – November 2026. Source: UNODA; Lieber Institute West Point, May 2026.
35. NATO, principles of the responsible use of artificial intelligence in defence (2021) and the revised AI strategy.
36. The Act of 8 December 2006 on the Polish Air Navigation Services Agency (Journal of Laws of 2025, item 1267), including the Agency’s extended competences in the area of unmanned systems.
37. The Act of 29 May 2026 amending the Act on Crisis Management and certain other acts (Journal of Laws of 2026, item 815) – implementation of the CER Directive; the powers of critical infrastructure operators to use jamming devices (from 26 June 2026); the new Chapter 6a concerning unmanned floating objects; the extension of the powers of the Police, the Border Guard, the State Protection Service and the Military Gendarmerie; security audits; the Maritime Security Centre.
38. The Act of 11 March 2022 on the Defence of the Homeland.
39. The draft deregulatory amendment of the Aviation Law, transmitted by the Civil Aviation Authority to the Ministry of Infrastructure on 5 May 2026 (the system of penalties, insurance, notifications, protection of critical infrastructure, counter-drone systems) (at present no publication of the source text – see the footnotes referring to press information sources).
40. Directive 2014/53/EU on radio equipment (essential requirements, harmful interference).
41. Regulation (EU) 2019/452 establishing a framework for the screening of foreign direct investments; the Act of 24 July 2015 on the control of certain investments.
[1] https://www.youtube.com/watch?v=GCOeO35PQh8 Cf. the analytical material of a Polish commentator on the war and new technologies, based on accounts attributed to Ukrainian military intelligence (HUR), where it was indicated that Russia is producing “more Shaheds of the Geran 4 and 5 model, i.e. the jet variants, than Geran 2 drones, i.e. the piston ones – 3,000 jet-powered per month and 2,800 piston-powered.”
[2] Paweł Jeżowski, Rosja 2026: Koniec snu Putina o Imperium [Russia 2026: The End of Putin’s Dream of Empire] – Paweł Jeżowski https://www.youtube.com/watch?v=JSA9sh44Qj4&t=27s
[3] European Commission, Communication from the Commission to the European Parliament and the Council – Action Plan on Drone and Counter Drone Security, COM(2026) 81 final, 11 February 2026.
[4] Treaty on the Functioning of the European Union, Article 288 – the legal character of regulations, directives and other instruments of EU law.
[5] The Act of 29 May 2026 amending the Act on Crisis Management and certain other acts, Journal of Laws of 2026, item 815.
[6] The governmental bill amending the Act on Crisis Management and certain other acts, Sejm print no. 2355, the explanatory memorandum to the bill.
[7] The Act of 29 May 2026 amending the Act on Crisis Management and certain other acts, Journal of Laws of 2026, item 815, introducing, inter alia, Article 16c into the Act of 26 April 2007 on Crisis Management. Text of the act: https://eli.gov.pl/eli/DU/2026/815/ogl/pol
[8] The Act of 26 April 2007 on Crisis Management, Article 16c, added by the Act of 29 May 2026.
[9] The Act of 3 July 2002 – Aviation Law, Article 156ze(1).
[10] The governmental bill amending the Act on Crisis Management and certain other acts, Sejm print no. 2355, together with the explanatory memorandum, Sejm of the Republic of Poland, 10th term: https://www.sejm.gov.pl/Sejm10.nsf/druk.xsp?nr=2355
[11] Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (the AI Act), Article 6 and Article 113.
[12] The regulation amending Regulation (EU) 2024/1689 as regards the dates of application of the obligations concerning high-risk AI systems.
[13] Council on Foreign Relations (CFR) The CFR indicates that the war in Ukraine has led to a hitherto unseen pace of innovation in unmanned systems: “the Russia-Ukraine war is driving innovations in autonomous warfare not seen on other battlefields.” Kristen Thompson, How the Drone War in Ukraine Is Transforming Conflict, Council on Foreign Relations, 16 January 2024.
[14] The Carnegie Endowment for International Peace describes the conflict as a “living laboratory” for new doctrines of warfare: “both sides are now engaged in a sustained effort to gain advantage through rapid innovation and adaptation, introducing new types of unmanned systems, countermeasures, and operating methods at unprecedented speed.” Andriy Zagorodnyuk, The New Revolution in Military Affairs, Carnegie Endowment for International Peace, 2026.
[15] CSIS – Center for Strategic and International Studies The CSIS report describes how, after the start of the full-scale invasion, Ukraine created within about three years an entirely new defence technology ecosystem based on drones, shortening development cycles from multi-year military programmes to months. Kateryna Bondar, Unleashing U.S. Military Drone Dominance: What the United States Can Learn from Ukraine, Center for Strategic and International Studies (CSIS), 18 July 2025.
[16] K. Bondar, Unleashing U.S. Military Drone Dominance: What the United States Can Learn from Ukraine, Center for Strategic and International Studies (CSIS), 2025. The author indicates that the war in Ukraine has radically shortened the cycles of development and deployment of drone technologies: solutions whose development in classic military programmes took many years are now designed, tested and deployed in periods counted in months. Link: https://www.csis.org/analysis/unleashing-us-military-drone-dominance-what-united-states-can-learn-ukraine , Michael Kofman, Rob Lee, Not Built for Purpose: The Russian Military’s Ill-Fated Force Design, Center for a New American Security / Carnegie Endowment for International Peace, an analysis of the technological adaptation of both sides of the conflict and the role of the rapid iteration of unmanned systems.
Link: https://carnegieendowment.org International Institute for Strategic Studies (IISS), The Military Balance 2025, chapters on the Russo-Ukrainian war and the development of unmanned systems. The IISS indicates that the conflict in Ukraine has led to the mass use of drones as a basic element of combat operations and has accelerated the development of technologies for countering unmanned systems. Link: https://www.iiss.org/publications/the-military-balance/
Samuel Bendett, Russia’s War in Ukraine: The Role of Unmanned Systems and the Future of Warfare, Center for Naval Analyses (CNA). Bendett’s analyses frequently indicate that the war in Ukraine has become a “laboratory” for the rapid evolution of unmanned systems, in which the innovation cycle has been shortened from years to months.
Link: https://www.cna.org/
[17] https://www.youtube.com/watch?v=vI1W4bYCuNA&t=181s; thus General Skrzypczak in the press service: “the 7th day of the offensive operation conducted by the Russians is ending. The Russians have not achieved their main objectives, the objectives of the operation, that is they have not captured and have not managed to carry out the encirclement of Kyiv and have not come out on the Mykolaiv axis towards Odesa in order to encircle it jointly with a naval landing. On the auxiliary axes they achieved limited success; they approached Kharkiv and Mariupol; they took Zaporizhzhia. The problem is that the Russians have lost their momentum; the offensive has been halted essentially along the entire front line; the Russians are preparing, trying to bring up reserves, to reconstitute the forces that are prepared, in order to prepare them for combat, but at this moment they do not have such capabilities.”
[18] In practice, it is precisely at this point that the real value of legal advice for companies from the UAV and dual-use sector begins. For the same product may simultaneously be subject to the rules of aviation law, export law, data protection, cybersecurity, AI compliance and contractual restrictions connected with its further use by the client or integrator. Effective advice therefore does not consist in the analysis of a single provision in isolation from the rest, but in building a coherent risk map: from the classification of the product and the market entry model, through the assessment of compliance obligations and export restrictions, to the structure of contracts, responsibility for implementation and the security of project financing. In the drone sector, the advantage today is gained not only by those who develop better technology, but also by those who are able to order its legal and transactional status earlier in many jurisdictions simultaneously.
[19] Lieber Institute at West Point, Whose Decision Was It? Drone Swarms and the Accountability Gap in Ukraine, 25 July 2026.
[20] Commission Delegated Regulation (EU) 2019/945 of 12 March 2019 on unmanned aircraft systems and on third-country operators of unmanned aircraft systems, OJ EU L 152 of 11.06.2019, p. 1.
[21] Commission Implementing Regulation (EU) 2019/947 of 24 May 2019 on the rules and procedures for the operation of unmanned aircraft, in particular Article 14 (the operator registration obligation). The character of the operator registration obligation, including for drones equipped with sensors capable of capturing personal data, is also explained by EASA.
[22] Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR), in particular Article 4(1), Article 5, Article 6 and Article 35.
[23] Judgment of the Court of Justice of 11 December 2014, František Ryneš v Úřad pro ochranu osobních údajů, C-212/13, EU:C:2014:2428.
[24] Regulation (EU) 2021/821 of the European Parliament and of the Council of 20 May 2021 setting up a Union regime for the control of exports, brokering, technical assistance, transit and transfer of dual-use items.
[25] Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (the AI Act), in particular Article 3, Article 6 and Annexes I and III.
[26] DJI (full name: SZ DJI Technology Co., Ltd., also referred to as Shenzhen DJI Sciences and Technologies Ltd.) is a private technology company with its registered office in Shenzhen in the People’s Republic of China, founded in 2006 by Frank Wang. The company specialises in the production of commercial and professional unmanned systems, image stabilisers, cameras, aerial imaging devices and solutions for consumer, industrial and agricultural applications. Its most recognisable product lines include, inter alia, Mavic, Mini, Air, Avata, Matrice, Agras and the Osmo line of handheld devices. In the trade literature and media coverage, DJI is commonly described as the largest manufacturer of consumer drones in the world, whereby, owing to the private character of the company, data on its precise revenues and sales volumes are not fully public; publicly available sources point, however, to the global scale of its activity, employment counted in the thousands, and a dominant position in the segment of civil camera drones; https://www.reuters.com/article/technology/game-of-drones-chinese-giant-dji-hit-by-us-tensions-staff-defections-idUSKBN2AZ0PV/
[27] https://odessa-journal.com/the-ukrainian-company-has-unveiled-the-zoom-drone-as-an-alternative-to-the-chinese-dji-mavic
[28] https://rubryka.com/ru/2024/10/21/ukrayinska-kompaniya-rozrobyla-dron-rozvidnyk-zoom-u-nishi-dji-mavic/
[29] https://www.frontline-robotics.tech/en#product
[30] The NATO Codification System (NCS) does not derive from a single statute or regulation, but from NATO’s allied standardisation-logistics system, managed by Allied Committee 135 (AC/135). The basic system document is ACodP-1 (NATO Manual on Codification / AC/135 Codification Manual), which sets out the principles, responsibilities and procedures of codification. The system further rests on a series of NATO standardisation agreements (STANAG), in particular STANAG 3150, STANAG 3151, STANAG 4199 and STANAG 4438.
https://www.dla.mil/Working-With-DLA/Federal-and-International-Cataloging/NATO
[31] https://www.atlanticcouncil.org/blogs/ukrainealert/fpv-drones-in-ukraine-are-changing-modern-warfare/
[32] https://vgi.com.ua/en/the-race-for-drone-independence-ukraines-fpv-component-ecosystem/
[34] https://www.kmu.gov.ua/en/news/v-ukraini-zapustyly-defense-tech-cluster-brave1-iakyi-stymuliuvatyme-rozvytok-viiskovykh-innovatsii-ta-oboronnykh-tekhnolohii
https://egrants.com.ua/en/programs/grant-for-the-development-of-components-for-unmanned-systems
[35] https://www.aspistrategist.org.au/the-underexploited-potential-of-ukrainian-defence-tech/
[36] https://digitalstate.gov.ua/news/tech/brave1-market-ukrayina-zapuskaye-marketpleys-viyskovykh-innovatsiy
[37] https://www.nationaldefensemagazine.org/articles/2025/5/28/as-russia-ukraine-war-continues-so-does-drone-innovation
[38] https://cms.egrants.com.ua/assets/4621da83-b816-4967-8328-b9223a6c0d1c
[39] https://usf.com.ua/en/about-usf
[40] https://www.eeas.europa.eu/delegations/ukraine/eu4ua-defence-tech-eu-and-ukraine-launch-new-%E2%82%AC33-million-brave1-grant-programme_en
[41] See Cabinet of Ministers of Ukraine, Ukraine launches BRAVE1 defence tech cluster to stimulate development of military innovations and defence technologies; cf. also Brave1, About Brave1, where it is indicated that Brave1 is a governmental initiative directed at the development of defence technologies, implemented by the Innovation Development Fund and initiated by the competent state organs and the components of Ukraine’s security and defence sector.
See EEAS / Delegation of the European Union to Ukraine, EU4UA Defence Tech: EU and Ukraine launch new EUR 3.3 million BRAVE1 grant programme, indicating that the project is financed by the European Union and implemented by BRDO in cooperation with Brave1; cf. also BRDO, Strengthening the Innovation Capacities of the Ukrainian Defence Technological Industrial Base, where the title of the implementation project linked with the EU4UA Defence Tech initiative was disclosed.
See Regulations for the Brave1 EU4UA Defence Tech Grant Program, available in the Legal Terms section of the programme Grant for the development of components for unmanned systems on the eGrants platform; cf. also the Digital State communication, indicating that EU4UA Defence Tech is financed by the European Union and implemented by BRDO in cooperation with Brave1.
https://egrants.com.ua/en/programs/grant-for-the-development-of-components-for-unmanned-systems
[42] The concept of the radio horizon should be treated as a technical, not a normative, term. It does not function as a legal definition in the EASA regime, in U-space or in the classic acts of electronic communications law. Its legal significance is, however, obvious, because it describes a material limitation of communications on which the possibility of conducting unmanned operations beyond the direct line of sight depends, and thus it indirectly affects the assessment of the conformity of radio equipment, the safety of operations, the design of BVLOS architecture and liability for the continuity and reliability of transmission.
[43] https://interoperable-europe.ec.europa.eu/collection/rolling-plan-ict-standardisation/u-space-0
[44] https://militaeraktuell.at/en/ukraine-opens-next-round-in-drone-frequency-war/;
[45] Mesh modems turn Shaheds into FPV drones: how enemy technology works:
https://dev.ua/en/news/mesh-modemy-u-shakhedakh-peretvoriuiut-ikh-na-fpv-drony-1762344495
[46] https://dronexl.co/2026/02/28/ukraine-shahed-drone-relay-stations-belarus/
[47] https://www.atlanticcouncil.org/blogs/ukrainealert/fiber-optics-drones-have-emerged-as-critical-kit-for-both-russia-and-ukraine/, https://www.washingtonpost.com/world/2025/05/23/ukraine-russia-drones-fiberoptic-jamming/
[48] https://www.act.nato.int/article/innovation-challenge-fibre-optic-drones/
[49] European Commission, Joint Research Centre, C-UAS detection, tracking and identification technology.
https://publications.jrc.ec.europa.eu/repository/bitstream/JRC140692/JRC140692_01.pdf
Alex Braszko, Center for Army Lessons Learned, August 12, 2025; Fiber Optic Drones: Posing a Significant C-UAS Challenge – https://www.army.mil/article/287737/fiber_optic_drones_posing_a_significant_c_uas_challenge
[50] https://csrc.nist.gov/glossary/term/spoofing, https://www.faa.gov/about/office_org/headquarters_offices/avs/offices/afx/afs/afs400/afs410/GNSS/GPS_GNSS_Interference_Resource_Guide.pdf
[51] https://www.armyrecognition.com/archives/archives-defense-exhibitions/2026-archives-news-defense-exhibitions/bedex-2026/ukraine-to-export-combat-proven-vampire-heavy-drone-for-night-strikes-and-mine-laying
[52] https://united24media.com/latest-news/russia-forms-units-of-agricultural-drones-to-mirror-ukrainian-tactics-7371
[53] https://www.pravda.com.ua/eng/articles/2026/01/15/8016293/ ; https://united24media.com/defense-tech/a-russian-drone-that-takes-off-every-minute-along-ukraines-front-how-do-you-stop-molniya-19647
[54] https://github.com/cognis-digital/awesome-drone-warfare-osint/blob/main/docs/drones/lancet.md
[55] https://defence-blog.com/ukraine-fields-new-recon-strike-drone/
[56] https://www.wbgroup.pl/en/produkt/warmate-loitering-munnitions/, https://en.wikipedia.org/wiki/WB_Electronics_Warmate
[57] https://english.nv.ua/nation/ukraine-fields-the-low-cost-fp-1-long-range-drone-nv-discloses-the-uav-specs-50559428.html;
[58] https://bavovna.ai/uav/fp-1/;
[59] See NV, How Ukraine-made FP-1 drone reshapes long-range strikes; Militarnyi, Ukrainian Fire Point Establishes In-House Production of Engines for Long-Range Drones; Reuters, Ukrainian drones hit Russia’s largest refinery, in one of deepest strikes yet; cf. also UNN and RBC-Ukraine in relation to the attack on Omsk and the scale of FP-1 production NV Militarnyi Reuters UNN RBC-Ukraine.
[60] See the MTCR Guidelines, the official MTCR website, indicating the division of the control annex into Category I and Category II; cf. also U.S. Department of State, Missile Technology Control Regime (MTCR) Frequently Asked Questions, where it is indicated that Category I covers complete rocket systems and unmanned aerial vehicle systems capable of delivering a payload of at least 500 kg to a range of at least 300 km; as regards the absorption of this logic into EU law, see Regulation (EU) 2021/821 setting up a Union regime for the control of exports of dual-use items. MTCR U.S. Department of State EUR-Lex; https://www.state.gov/bureau-of-international-security-and-nonproliferation/releases/2025/01/missile-technology-control-regime-mtcr-frequently-asked-questions
[61] On the significance of long-range communications for modern drone operations, see Atlantic Council, The coming compute war in Ukraine; on terminal guidance / machine vision enabling autonomous terminal-phase homing, see Modern War Institute, Battlefield Drones and the Accelerating Autonomous Arms Race in Ukraine and Defense Express, How Ukrainian FPV Drones With Automated Terminal Guidance Work; https://mwi.westpoint.edu/battlefield-drones-and-the-accelerating-autonomous-arms-race-in-ukraine/
[62] See Article 2(3) and recital 24 of Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (the AI Act), which exclude from the regulation’s scope AI systems used exclusively for military, defence or national security purposes; cf. also the discussions on autonomous weapon systems (LAWS) conducted within the framework of the Convention on Certain Conventional Weapons (CCW), in particular the work of the Group of Governmental Experts on Lethal Autonomous Weapons Systems (GGE on LAWS).
[63] See EASA, Easy Access Rules for Unmanned Aircraft Systems, revision from June 2026, indicating that this revision incorporates the AMC and GM to Regulation (EU) 2019/947 stemming from ED Decision 2025/018/R; cf. also the online version of the publication of 30 June 2026. EASA EASA online publication.
[64] See European Parliamentary Research Service, Defence and artificial intelligence (2025), indicating that the European Parliament adopted two main resolutions concerning LAWS and military AI – in 2018 and 2021; cf. also EEAS, Autonomous weapons must remain under human control, Mogherini says at European Parliament. EPRS PDF EEAS
[65] See European Parliament Legislative Train, Digital Omnibus on AI, indicating that the proposal formed part of the package published on 19 November 2025; cf. also EPRS, Digital Omnibus on AI, where it is indicated that the co-legislators reached agreement in the trilogue on 7 May 2026, and the Parliament approved it on 16 June 2026; on the final adoption by the Council, see Consilium, Artificial Intelligence: Council gives final green light to simplify and streamline rules, 29 June 2026; the final act: Regulation (EU) 2026/1744. Legislative Train EPRS PDF Consilium EUR-Lex;
[66] Regulation (EU) 2021/821 entered into force on 9 September 2021 as the new basic act of the Union’s system for the control of exports of dual-use items, replacing the earlier Regulation (EC) No 428/2009. The reference to 15 November 2025 does not mean that the act “ends” in 2025, but that from that day the cited consolidated version applies, taking account of the amendments to the text so far. The date of 8 September 2025, in turn, refers to one of the updates of the control lists / annexes. In August 2026, the regulation still remains an act in force.
[67] The transfer of model weights means the transfer of the trained parameters of the AI model themselves – that is, the numbers which the model “carries within itself” after training and on the basis of which it operates.
[68] See Regulation (EU) 2021/697 of the European Parliament and of the Council of 29 April 2021 establishing the European Defence Fund; cf. also the European Defence Fund (2021–2027) on EUR-Lex and the European Commission’s official website concerning the EDF. EUR-Lex EUR-Lex summary European Commission;
[69] See Regulation (EU) 2023/2418 of the European Parliament and of the Council of 18 October 2023 establishing an instrument for the reinforcement of the European defence industry through common procurement (EDIRPA); cf. also the EUR-Lex summary and the European Commission’s official website concerning EDIRPA. EUR-Lex EUR-Lex summary European Commission;
[70] ASAP was established by Regulation (EU) 2023/1525 of the European Parliament and of the Council of 20 July 2023 as an instrument supporting the increase of the production capacities of European industry in the field of ammunition and missiles; the logic of this act – consisting in the public strengthening of the production capabilities of the defence industry – is functionally transferable also to the mass production of loitering munitions and drones. EUR-Lex European Commission;
[71] SAFE (Security Action for Europe) was established by Council Regulation (EU) 2025/1106 of 27 May 2025 as a new instrument strengthening European defence capabilities and the defence industry through financial mechanisms and the support of coordinated actions of the Member States; it remains a current element of the EU defence architecture also in 2026. EUR-Lex Consilium;
[72] See Regulation (EU) 2025/2643 of the European Parliament and of the Council of 16 December 2025 establishing the European Defence Industry Programme (EDIP); cf. also the European Commission’s official website concerning EDIP. EUR-Lex European Commission;
[73] This is a broader European Commission package, adopted on 17 June 2025, intended to create a “defence-readiness mindset” and to simplify the regulatory environment for defence investment. The Commission itself describes it as a comprehensive package and a simplification proposal, and the Parliament in the Legislative Train speaks outright of a Communication on the Defence Readiness Omnibus. It is therefore not simply “the same as EDIP”, but rather a deregulatory-simplification package and the political-legislative environment for faster action by the defence sector. European Commission Legislative Train
[74] See European Commission, Readiness Roadmap 2030 and White Paper for European Defence – Readiness 2030, indicating the four flagship projects: Eastern Flank Watch, the European Drone Defence Initiative, the European Air Shield and the European Space Shield. European Commission White Paper.
[75] Regulation (EU) 2023/588 of the European Parliament and of the Council of 15 March 2023 establishing the Union Secure Connectivity Programme for the period 2023–2027. eur-lex.europa.eu.
[76] Directive (EU) 2022/2555 (NIS2) of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union. eur-lex.europa.eu.
[77] Directive (EU) 2022/2557 (CER) of the European Parliament and of the Council of 14 December 2022 on the resilience of critical entities. eur-lex.europa.eu.
[78] Regulation (EU) 2024/2847 (the Cyber Resilience Act, CRA) of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements. eur-lex.europa.eu.
[79] See EDPB/EDPS Joint Opinion 2/2026 of 11 February 2026 on the Digital Omnibus and the EDPB communication of the same day; as to the further negotiating stage and the withdrawal of the text from COREPER II at the end of June 2026, cf. the expert source: Privacy Next, Digital Omnibus Negotiations (GDPR) – July 2026 Update. EDPB Joint Opinion 2/2026 Privacy Next.
[80] See Article 36 of Additional Protocol I of 1977 to the Geneva Conventions; cf. also ICRC, A Guide to the Legal Review of New Weapons, Means and Methods of Warfare. ICRC art. 36 ICRC Guide.
[81] See CCW/MSP/2023/7, para. 20, in which the mandate of the Group of Governmental Experts (GGE) on emerging technologies in the area of lethal autonomous weapons systems (LAWS) was defined as the further consideration and formulation, “by consensus”, of a set of elements of an instrument, without prejudging its character; see also CCW/GGE.1/2026/WP.2, paras. 3–5, 76–78. The Seventh CCW Review Conference has been scheduled for 16–20 November 2026 in Geneva (CCW/MSP/2025/8, para. 19(g); see also UN Secretary-General, Letter convening the Seventh Review Conference of the CCW, April 2026).
[82] NATO, Summary of the NATO Artificial Intelligence Strategy, 22 October 2021, paras. 7–10, in particular para. 9, containing the six Principles of Responsible Use for AI in Defence: Lawfulness, Responsibility and Accountability, Explainability and Traceability, Reliability, Governability and Bias Mitigation; NATO, Summary of NATO’s revised Artificial Intelligence (AI) strategy, 10 July 2024, paras. 2, 5-10. The revised strategy of 2024 confirms the applicability of the six principles of the responsible use of AI and provides for their further operationalisation, inter alia through standards, assessment and testing procedures (TEV&V) and certification mechanisms.
[83] https://www.swiatdronow.pl/podsumowanie-posiedzenia-podkomisji-stalej-do-spraw-lotnictwa-cywilnego-10-06-2026-r; Record of the proceedings of the Standing Subcommittee on Civil Aviation (no. 10) of 10 June 2026, Sejm of the Republic of Poland, in particular the statement of the Director of the Unmanned Aircraft Department of the Civil Aviation Authority, Paweł Szymański, who indicated that the draft amendment concerning unmanned aircraft systems prepared by the Civil Aviation Authority was transmitted to the Ministry of Infrastructure on 5 May 2026, constituting a response to the postulates of civil society and the problems revealed in the practice of applying the new provisions; the draft was described as being of a deregulatory, clarifying and ordering character, covering, inter alia, a change of the regulations concerning mandatory third-party liability insurance and sanctions. https://www.sejm.gov.pl/sejm10.nsf/biuletyn.xsp?SessionID=55B1AE69A4EDC2996BDD70EE751F3A4A86C14EE1&documentId=2AEF7DEF0751F54BC1258E22003E5D23&utm
[84] The postulate of meaningful human control does not currently constitute a separate, binding norm of international law. It is a concept developed within the framework of the negotiations concerning autonomous weapon systems, whose purpose is to ensure that the human retains real control over the application of force. Its legal justification is connected above all with the obligation to comply with the existing norms of international humanitarian law, in particular the principles of distinction, proportionality and the taking of precautionary measures, and the obligation to review new means and methods of warfare on the basis of Article 36 of Additional Protocol I.
[85] Article 6zj(1)–(4) of the Act of 26 April 2007 on Crisis Management, in the wording given by the Act of 29 May 2026 amending the Act on Crisis Management and certain other acts, Journal of Laws of 2026, item 815, in conjunction with Article 156ze(1) of the Act of 3 July 2002 – Aviation Law, consolidated text: Journal of Laws of 2025, item 1431, as amended.
[86] Article 2(2)(d) and Article 2(3) of Regulation (EU) 2021/821 of the European Parliament and of the Council of 20 May 2021 setting up a Union regime for the control of exports, brokering, technical assistance, transit and transfer of dual-use items, in the current consolidated text; see also Commission Recommendation (EU) 2021/1700 of 15 September 2021 on internal compliance programmes for controls of research involving dual-use items: Regulation 2021/821 and Recommendation 2021/1700.
[87] The Act of 24 July 2015 on the control of certain investments (consolidated text: Journal of Laws of 2026, item 47, as amended).